Enalean Tuleap是法国Enalean公司的一个自由的开源工具。用于应用程序和系统开发的端到端可追溯性。 Enalean Tuleap存在跨站请求伪造漏洞,该漏洞源于规划管理API缺少CSRF保护,可能导致创建、编辑或删除计划。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-64497 | 6.5 MEDIUM | Tuleap exposes releases for all projects to File Release System project administrators |
| CVE-2025-64498 | 4.6 MEDIUM | Tuleap has a Cross-Site Request Forgery (CSRF) vulnerability |
| CVE-2025-64760 | 4.6 MEDIUM | Tuleap has missing CSRF protections in its tracker trigger management system |
| CVE-2025-65962 | 4.6 MEDIUM | Tuleap has missing CSRF protections its in tracker field dependencies |
No comments yet