VYPR
High severity8.8NVD Advisory· Published Mar 5, 2020· Updated Jun 17, 2026

CVE-2019-20107

CVE-2019-20107

Description

Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Testlink/Testlink2 versions
    cpe:2.3:a:testlink:testlink:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:testlink:testlink:*:*:*:*:*:*:*:*range: <=1.9.19
    • (no CPE)range: <=1.9.19
  • TestLink/TestLinkdescription

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.