Medium severity6.1NVD Advisory· Published Jan 20, 2020· Updated Jun 17, 2026
CVE-2019-20381
CVE-2019-20381
Description
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TestLink/TestLinkdescription
Patches
Vulnerability mechanics
References
3- github.com/TestLinkOpenSourceTRMS/testlink-code/commit/cde692895e425731e6951d265a01ca6425a7c26envdPatchThird Party Advisory
- mantis.testlink.org/view.phpnvdIssue TrackingThird Party Advisory
- github.com/TestLinkOpenSourceTRMS/testlink-code/compare/1.9.19...1.9.20nvdThird Party Advisory
News mentions
0No linked articles in our index yet.