Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown
CVE-2024-42906
Disclosure Date: August 26, 2024 (last updated September 06, 2024)
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
0
Attacker Value
Unknown
CVE-2023-50110
Disclosure Date: December 30, 2023 (last updated January 06, 2024)
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
0
Attacker Value
Unknown
CVE-2022-35196
Disclosure Date: September 20, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
0
Attacker Value
Unknown
CVE-2022-35194
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.
0
Attacker Value
Unknown
CVE-2022-35195
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
0
Attacker Value
Unknown
CVE-2022-35193
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
0
Attacker Value
Unknown
CVE-2020-12274
Disclosure Date: April 27, 2020 (last updated November 27, 2024)
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
0
Attacker Value
Unknown
CVE-2020-12273
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
0
Attacker Value
Unknown
CVE-2020-8638
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
0
Attacker Value
Unknown
CVE-2020-8637
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
0