Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports.
Impact
An attacker with the capability to create a new tracker can execute arbitrary SQL queries.
CVSSv3.1 score: 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Exploitation
Create a tracker with the attached tracker XML structure and try to display the column in a report.
References
CWE-89
OWASP SQL Injection
CVE-2022-31058