CVE-2023-23938 MEDIUM

CVE-2023-23938: Cross-site Scripting (XSS) through the name of a color of select box values in tuleap

Vendor Enalean
Product tuleap
Weakness CWE-79 · XSS
Published April 20, 2023
Last update February 5, 2025

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are subject to a cross site scripting attack which can be injected in the name of a color of select box values of a tracker and then reflected in the tracker administration. Administrative privilege is required, but an attacker with tracker administration rights could use this vulnerability to force a victim to execute uncontrolled code in the context of their browser. This issue has been addressed in Tuleap Community Edition version 14.5.99.4. Users are advised to upgrade. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

April 20, 2023 CVE published
February 5, 2025 Record updated