Skip to main content

CVE-2014-8791

CVSS Score Not Available
52.40%
MEDIUM RiskEPSS (98th percentile)

project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

Published: 12/2/2014
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

52.40%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 52.40% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.