PT-2025-9510 · Unknown+1 · Tuleap Enterprise Edition+2

Tgerbet

+1

·

Published

2025-03-03

·

Updated

2025-07-10

·

CVE-2025-27099

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tuleap versions prior to 16.4.99.1740067916 Tuleap Enterprise Edition versions prior to 16.4-5 and 16.3-10
Description Tuleap is an Open Source Suite to improve management of software developments and collaboration. It allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this issue to force other tracker administrators to execute uncontrolled code.
Recommendations For Tuleap versions prior to 16.4.99.1740067916, update to Tuleap Community Edition 16.4.99.1740067916 or later. For Tuleap Enterprise Edition versions prior to 16.4-5, update to Tuleap Enterprise Edition 16.4-5 or later. For Tuleap Enterprise Edition versions prior to 16.3-10, update to Tuleap Enterprise Edition 16.3-10 or later. As a temporary workaround, consider restricting access to the tracker names used in the semantic timeframe deletion message until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27099
GHSA-VQFJ-2GQP-G89X

Affected Products

Tuleap
Tuleap Community Edition
Tuleap Enterprise Edition