Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #41858 XSS via the tracker names used in the semantic timeframe deletion message
    Infos
    #41858
    Thomas Gerbet (tgerbet)
    2025-03-03 09:32
    2025-02-20 16:26
    43589
    Details
    XSS via the tracker names used in the semantic timeframe deletion message

    The message explaining why a specific field cannot be removed when used by a semantic can contain unescaped information.

    Impact

    A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force other tracker administrators to execute uncontrolled code.

    CVSSv3.1 score: 4.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L)

    Exploitation

    In 2 trackers have a semantic timeframe with one inherited from the other.
    Rename the "source" tracker to something like "><script>alert(1)</script>, open the field administration of the other tracker.

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2025-27099

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-02-20
    Attachments
    Empty
    References
    Referenced by request #41858

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-21 09:11

    CVE-2025-27099 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes