CVE-2025-30203 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition RSS Widget cross site scripting
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been rated as problematic. Impacted is an unknown function of the component RSS Widget. This manipulation causes improper neutralization of encoded uri schemes in a web page.
This vulnerability is tracked as CVE-2025-30203. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.