Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2022-35196

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
Attacker Value
Unknown

CVE-2022-35194

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.
Attacker Value
Unknown

CVE-2022-35195

Disclosure Date: September 16, 2022 (last updated October 08, 2023)
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
Attacker Value
Unknown

CVE-2022-35193

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
Attacker Value
Unknown

CVE-2020-12274

Disclosure Date: April 27, 2020 (last updated November 27, 2024)
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
Attacker Value
Unknown

CVE-2020-12273

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
Attacker Value
Unknown

CVE-2020-8638

Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
Attacker Value
Unknown

CVE-2020-8637

Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
Attacker Value
Unknown

CVE-2020-8639

Disclosure Date: April 03, 2020 (last updated February 21, 2025)
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.