[POC] Account takeover due to CSRF vulnerability on Tuleap ALM platform CVE2018-7634

Опубликовано: 19 Март 2026
на канале: Mustafa İran
177
3

Tuleap is an application lifecycle management  (ALM) platform. It has features like project management, issue tracking, test management, document management etc. Tuleap used by well known/big companies like Airbus, Eclipse, Sodern etc. (according to the site).  HERE is a link about its features.

I 've found simple yet critical CSRF vulnerability on mail change function. The vulnerability leads to account takeover. Below there is a POC video. CVE-2018-7634 has assigned to the vulnerability.