Vulnerabilities > Enalean > Tuleap > 7.6

DATE CVE VULNERABILITY TITLE RISK
2018-09-21 CVE-2018-17298 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Enalean Tuleap
An issue was discovered in Enalean Tuleap before 10.5.
network
low complexity
enalean CWE-640
5.0
2018-03-12 CVE-2018-7538 SQL Injection vulnerability in Enalean Tuleap
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
network
low complexity
enalean CWE-89
7.5
2017-10-30 CVE-2017-7411 Code Injection vulnerability in Enalean Tuleap
An issue was discovered in Enalean Tuleap 9.6 and prior versions.
network
low complexity
enalean CWE-94
6.5
2017-04-29 CVE-2017-7981 OS Command Injection vulnerability in multiple products
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin.
network
low complexity
enalean phpwiki-project CWE-78
critical
9.0
2014-12-02 CVE-2014-8791 Code Injection vulnerability in Enalean Tuleap 7.6
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
network
enalean CWE-94
6.0