Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
History

Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
Title Tuleap allows XSS via the content of RSS feeds in the RSS widgets
Weaknesses CWE-79
CWE-84
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-31T18:34:00.583Z

Reserved: 2025-03-18T18:15:13.849Z

Link: CVE-2025-30203

cve-icon Vulnrichment

Updated: 2025-03-31T16:00:18.423Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-31T16:15:25.473

Modified: 2025-04-01T20:26:22.890

Link: CVE-2025-30203

cve-icon Redhat

No data.