PT-2025-9510 · Unknown+1 · Tuleap Enterprise Edition+2
Tgerbet
+1
·
Published
2025-03-03
·
Updated
2025-07-10
·
CVE-2025-27099
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tuleap versions prior to 16.4.99.1740067916
Tuleap Enterprise Edition versions prior to 16.4-5 and 16.3-10
Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. It allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this issue to force other tracker administrators to execute uncontrolled code.
Recommendations
For Tuleap versions prior to 16.4.99.1740067916, update to Tuleap Community Edition 16.4.99.1740067916 or later.
For Tuleap Enterprise Edition versions prior to 16.4-5, update to Tuleap Enterprise Edition 16.4-5 or later.
For Tuleap Enterprise Edition versions prior to 16.3-10, update to Tuleap Enterprise Edition 16.3-10 or later.
As a temporary workaround, consider restricting access to the tracker names used in the semantic timeframe deletion message until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tuleap
Tuleap Community Edition
Tuleap Enterprise Edition