关键信息 漏洞标题 XSS via the content of RSS feeds in the RSS widgets 严重性 Moderate CVSS v3 base metrics: - Attack vector: Network - Attack complexity: Low - Privileges required: High - User interaction: Required - Scope: Changed - Confidentiality: None - Integrity: Low - Availability: Low CVE ID: CVE-2025-30203 Weaknesses: CWE-84 影响 A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. 受影响版本 Tuleap Community Edition (tuleap): < 16.5.99.1742562878 Tuleap Enterprise Edition (tuleap): - < 16.5-5 - < 16.4-8 修复版本 Tuleap Community Edition: 16.5.99.1742562878 Tuleap Enterprise Edition: - 16.5-5 - 16.4-8 更多信息 If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page. 参考链接 request #42243: XSS via the content of RSS feeds in the RSS widgets 54cce3f https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=54cce3f5e883d16055cb0239e023f48cdf5eb25f