XSS through the name of a color of select box values
Package
Tuleap Community Edition
(tuleap)
Affected versions
>= 13.8.99.49 && < 14.5.99.4
Patched versions
14.5.99.4
Tuleap Enterprise Edition
(tuleap)
< 14.5-2
< 14.4-7
14.5-2
14.4-7
XSS can injected in the name of a color of select box values of a tracker and then reflected in the tracker administration.
Impact
An attacker with tracker administration rights could use this vulnerability to force a victim to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References