Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #42177 Content injection via emails sent by the mass emailing features
    Infos
    #42177
    Thomas Gerbet (tgerbet)
    2025-03-04 17:38
    2025-02-26 10:03
    43908
    Details
    Content injection via emails sent by the mass emailing features

    The mass emailing features do not sanitize the content of the HTML emails.

    Impact

    A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients.

    CVSSv3.1 score: 4.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2025-27156

    Acknowledgements

    This issue has been found thanks to Psalm 6 taint analysis feature.

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-02-26
    Attachments
    Empty
    References
    Referenced by request #42177

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-28 18:05

    CVE-2025-27156 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes