Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Enalean Tuleap 信息泄露漏洞
Vulnerability Description
Enalean Tuleap是法国Enalean公司的一套开源的软件开发和项目管理工具。该工具提供企业应用程序生命周期管理,以及项目跟踪、源代码管理和团队协作等功能。 Enalean Tuleap 7.2及之前版本中存在XML外部实体漏洞,该漏洞源于程序执行创建操作时,plugins/tracker/ URL没有充分过滤XML文档。远程攻击者可利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A