Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-58953
HistoryJul 01, 2022 - 12:00 a.m.

Tuleap SQL Injection Vulnerability (CNVD-2022-58953)

2022-07-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14

0.002 Low

EPSS

Percentile

62.2%

Tuleap is an application lifecycle management system that facilitates agile software development, design projects, V-models, requirements management, and IT service management. SQL injection vulnerabilities exist in versions of Tuleap prior to 13.9.99.95, which stem from a failure of Tuleap to properly clean up user input when constructing SQL queries to retrieve data reported by the tracker. An attacker could exploit this vulnerability to execute arbitrary SQL queries.

CPENameOperatorVersion
Tuleap Tuleap <13.eq9.99.95

0.002 Low

EPSS

Percentile

62.2%

Related for CNVD-2022-58953