CVE-2014-8791: Enalean Tuleap

Medium severity, CVSS 6.0. EPSS: 14.8% chance of exploitation in the next 30 days.

project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

Affected products

Published 2014-12-02. Last modified 2026-06-17.