CVE Feed

    Dashboard / CVE / CVE-2017-7411

    CVE-2017-7411

    An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks (including but not limited to Remote Code Execution).

    Published:Oct 30, 2017
    Last Modified:Apr 20, 2025
    EPS:Oct 30, 2017
    EPSS Score:0.73892
    CVSS Score:8.8

    Affected Products

    Vendor
    Enalean
    Product
    Tuleap

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High