Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the capability to create a document could force victim to execute uncontrolled code. Users are advised to upgrade. There are no known workarounds for this issue.
{
"cwe_ids": [
"CWE-79"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31063.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-31063.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.9.99.111"
}
]
},
{
"events": [
{
"introduced": "13.8.0"
},
{
"fixed": "13.8.6"
}
]
},
{
"events": [
{
"introduced": "13.9.0"
},
{
"fixed": "13.9.3"
}
]
}
]