VYPR
Medium severity6.5NVD Advisory· Published Jun 29, 2022· Updated Jun 17, 2026

CVE-2022-31063

CVE-2022-31063

Description

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the capability to create a document could force victim to execute uncontrolled code. Users are advised to upgrade. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Enalean/Tuleap4 versions
    cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*range: <13.9.99.111
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*range: >=13.8.0,<13.8.6
    • (no CPE)range: <13.9.99.111
    • (no CPE)range: < 13.9.99.111

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.