Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.
2025-03-31T16:15:23.897
2025-08-21T22:09:47.850
Analyzed
CVSSv3.1: 4.6 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | enalean | tuleap | < 16.4-8 | Yes |
| Application | enalean | tuleap | < 16.5.99.1741784483 | Yes |
| Application | enalean | tuleap | < 16.5-3 | Yes |