CVE-2014-8791

Tuleap < 7.7 - Authenticated PHP Object Injection via Project Registration Data Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-8791. PoCs published by Metasploit, including Metasploit module exploits/unix/webapp/tuleap_unserialize_exec.

AI-analyzed exploit summary This Metasploit module exploits a PHP object injection vulnerability in Tuleap <= 7.6-4 via an authenticated POST request to 'project/register.php'. It leverages a crafted serialized payload to trigger arbitrary code execution through the destructor method of the Jabbex class.

Description

project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/35545

This Metasploit module exploits a PHP object injection vulnerability in Tuleap <= 7.6-4 via an authenticated POST request to 'project/register.php'. It leverages a crafted serialized payload to trigger arbitrary code execution through the destructor method of the Jabbex class.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Tuleap <= 7.6-4
Auth required
Prerequisites: Valid credentials for Tuleap · sys_create_project_in_one_step option disabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tuleap_unserialize_exec.rb

This Metasploit module exploits a PHP object injection vulnerability in Tuleap <= 7.6-4 via unsafe unserialize() in 'register.php'. It chains gadgets (Jabbex, Jabber, Transition_PostAction_FieldFactory) to execute arbitrary PHP code via eval() after authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Tuleap <= 7.6-4
Auth required
Prerequisites: Valid credentials · sys_create_project_in_one_step disabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71335
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534105/100/0/threaded
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/101
Exploit x_refsource_misc
http://karmainsecurity.com/KIS-2014-13

Scores

EPSS 0.1477
EPSS Percentile 96.2%

Details

CWE
CWE-94
Status published
Products (1)
enalean/tuleap 7.6
Published Dec 02, 2014
Tracked Since Feb 18, 2026