CVE-2014-8791: Enalean Tuleap
Medium severity, CVSS 6.0. EPSS: 14.8% chance of exploitation in the next 30 days.
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
Affected products
- Enalean Tuleap: version 7.6 only
Published 2014-12-02. Last modified 2026-06-17.