Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740567344 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740567344 and Tuleap Enterprise Edition 16.4-6 and 16.3-11. | |
Title | Tuleap allows content injection via emails sent by the mass emailing features | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-04T16:53:49.741Z
Updated: 2025-03-04T17:22:15.113Z
Reserved: 2025-02-19T16:30:47.780Z
Link: CVE-2025-27156

Updated: 2025-03-04T17:22:11.351Z

Status : Received
Published: 2025-03-04T17:15:18.997
Modified: 2025-03-04T17:15:18.997
Link: CVE-2025-27156

No data.