CVE-2022-31063

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
3.5
LOW
Affected
1
PROJECT

Description

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the capability to create a document could force victim to execute uncontrolled code. Users are advised to upgrade. There are no known workarounds for this issue.

Enalean/tuleap
Enalean/tuleapUNAVAILABLE
Tuleap is an Open Source Suite to improve management of software developments and collaboration. With a single web-based solution, project managers, developers & quality managers can easily build, deploy software projects.
GitHubGitHub
1.12K