XSS via the title of a document
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 13.9.99.111
Patched versions
13.9.99.111
Tuleap Enterprise Edition
(tuleap)
< 13.9-3
< 13.8-6
13.9-3
13.8-6
The title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents.
Impact
A malicious user with the capability to create a document could force victim to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References