CVE-2017-7411 is a second-order PHP object injection vulnerability in Enalean Tuleap versions 5.0 through 9.6. The vulnerability resides in the User::getRecentElements() method, which uses PHP's unserialize() function on user-controllable data stored in user preferences. Authenticated attackers with access to the REST API can manipulate these preferences to inject arbitrary PHP objects, potentially leading to remote code execution as the codendiadm user. The vulnerability was discovered by Egidio Romano and fixed in Tuleap version 9.7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting a Second-Order PHP Object Injection vulnerability (CVE-2017-7411) in Tuleap <= 9.6. The exploit requires valid user credentials and abuses the REST API to inject a malicious PHP object into user preferences. The attack leverages a PHP POP chain involving the Mustache class and the Transition_PostActionSubFactory::fetchPostActions() method, ultimately leading to arbitrary PHP code execution via eval(). The module is fully weaponized, allowing the attacker to supply any PHP payload (such as a reverse shell) through the Metasploit framework. The exploit interacts with several HTTP endpoints on the target Tuleap instance, including authentication, user preferences, and tracker plugin endpoints. The code is written in Ruby and follows the standard Metasploit module structure, with clear separation of authentication, payload injection, and execution logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.