CVE-2014-8791
CVSS Score Not Available
52.40%
MEDIUM RiskEPSS (98th percentile)
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
Published: 12/2/2014
Modified: 4/12/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
52.40%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 52.40% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.