Critical Vulnerability Information Vulnerability Title Missing CSRF protections when updating tracker general settings Vulnerability Impact Severity: Moderate (CVSS v3 score: 4.6/10) CVE ID: CVE-2025-64498 CVE Base Metrics: - Attack Vector: Network - Attack Complexity: Low - Required Privileges: Low - User Interaction: Required - Scope: Unchanged - Confidentiality: None - Integrity: Low - Availability: Low Affected Versions Tuleap Community Edition (tuleap): < 17.0.99.1762444754 Tuleap Enterprise Edition (tuleap): - < 17.0-2 - < 16.13-7 - < 16.12-10 Fixed Versions Tuleap Community Edition 17.0.99.1762444754 Tuleap Enterprise Edition: - 17.0-2 - 16.13-7 - 16.12-10 Description Attackers can exploit this vulnerability to trick victims into changing tracker general settings. Related References Related Issue #45593 Commit 993316d Related Code Commit Weakness CWE-352 (Cross-Site Request Forgery)