CVE-2025-30203 – Tuleap RSS Feed Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the
CVE-2025-30203 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 31, 2025

    Action Type Old Value New Value
    Added Description Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L
    Added CWE CWE-79
    Added CWE CWE-84
    Added Reference https://github.com/Enalean/tuleap/commit/54cce3f5e883d16055cb0239e023f48cdf5eb25f
    Added Reference https://github.com/Enalean/tuleap/security/advisories/GHSA-39gx-34fc-rx6r
    Added Reference https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=54cce3f5e883d16055cb0239e023f48cdf5eb25f
    Added Reference https://tuleap.net/plugins/tracker/?aid=42243
Share the Post:

Related Posts