Tuleap是Enalean开源的一个开源套件,旨在改善软件开发和协作的管理。 Tuleap存在跨站请求伪造漏洞,该漏洞源于跟踪器视图中的CSRF保护缺失,可能导致受害者提交或编辑工件或后续评论。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-30209 | 5.3 MEDIUM | Tuleap has improper permission handling in the REST endpoints and release notes display of |
| CVE-2025-30203 | 4.8 MEDIUM | Tuleap allows XSS via the content of RSS feeds in the RSS widgets |
| CVE-2025-29929 | 4.6 MEDIUM | Tuleap is missing CSRF protection on tracker hierarchy administration |
| CVE-2025-30155 | 4.3 MEDIUM | Tuleap does not enforce read permissions on parent trackers in the REST API |
No comments yet