PT-2025-13789 · Tuleap · Tuleap
Tgerbet
+1
·
Published
2025-03-31
·
Updated
2025-08-21
·
CVE-2025-30203
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tuleap versions prior to 16.5.99.1742562878
Tuleap Enterprise Edition versions prior to 16.5-5 and 16.4-8
Description
The issue allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this to force victims to execute uncontrolled code.
Recommendations
For Tuleap Community Edition versions prior to 16.5.99.1742562878, update to version 16.5.99.1742562878 or later.
For Tuleap Enterprise Edition versions prior to 16.5-5, update to version 16.5-5 or later.
For Tuleap Enterprise Edition versions prior to 16.4-8, update to version 16.4-8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tuleap