Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #43326 Missing CSRF protection on tracker canned responses administration
    Infos
    #43326
    Thomas Gerbet (tgerbet)
    2025-06-25 09:52
    2025-05-30 10:46
    45075
    Details
    Missing CSRF protection on tracker canned responses administration

    In the administration of a Tracker, in the "Canned responses", there is no CSRF protection when creating, updating or deleting a canned response.

    Impact

    An attacker could use this vulnerability to trick victims into changing the canned responses.
    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2025-48991

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-06-02
    Attachments
    Empty
    References
    Referenced by request #43326

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-06-02 14:13

    CVE-2025-48991 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes