CVE Feed

    Dashboard / CVE / CVE-2017-7981

    CVE-2017-7981

    Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax="c;id"' line to execute the id command.

    Published:Apr 29, 2017
    Last Modified:Apr 20, 2025
    EPS:Apr 29, 2017
    EPSS Score:0.25734
    CVSS Score:8.8

    Affected Products

    Vendor
    Enalean
    Product
    Tuleap
    Vendor
    Phpwiki Project
    Product
    Phpwiki

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High