Vulnerabilities > Enalean > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-41155 SQL Injection vulnerability in Enalean Tuleap
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration.
network
low complexity
enalean CWE-89
6.5
2021-10-15 CVE-2021-41147 SQL Injection vulnerability in Enalean Tuleap 11.151/11.161
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments.
network
low complexity
enalean CWE-89
6.5
2021-10-15 CVE-2021-41148 SQL Injection vulnerability in Enalean Tuleap 11.151/11.161
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments.
network
low complexity
enalean CWE-89
6.5
2018-09-21 CVE-2018-17298 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Enalean Tuleap
An issue was discovered in Enalean Tuleap before 10.5.
network
low complexity
enalean CWE-640
5.0
2018-03-01 CVE-2018-7634 Cross-Site Request Forgery (CSRF) vulnerability in Enalean Tuleap 9.17
An issue was discovered in Enalean Tuleap 9.17.
network
enalean CWE-352
6.8
2017-10-30 CVE-2017-7411 Code Injection vulnerability in Enalean Tuleap
An issue was discovered in Enalean Tuleap 9.6 and prior versions.
network
low complexity
enalean CWE-94
6.5
2014-12-02 CVE-2014-8791 Code Injection vulnerability in Enalean Tuleap 7.6
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
network
enalean CWE-94
6.0
2014-11-04 CVE-2014-7176 SQL Injection vulnerability in Enalean Tuleap
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
network
low complexity
enalean CWE-89
6.5
2014-10-31 CVE-2014-7177 XML External Entity Information Disclosure vulnerability in Enalean Tuleap
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
network
low complexity
enalean
4.0