Testlink Code
by Testlink
Source repositories
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-7390 | Cri | 0.64 | 9.8 | 0.02 | Sep 26, 2017 | SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php. | ||
| CVE-2018-7668 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2018 | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php. | ||
| CVE-2026-70561 | Med | 0.42 | 6.5 | 0.00 | Aug 7, 2026 | TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any… | ||
| CVE-2020-8639 | Hig | 0.04 | 8.8 | 0.16 | Apr 3, 2020 | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute… | ||
| CVE-2018-7466 | Hig | 0.04 | 7.5 | 0.06 | Feb 25, 2018 | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value. | ||
| CVE-2023-50110 | Hig | 0.00 | 7.5 | 0.01 | Dec 30, 2023 | TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used. | ||
| CVE-2020-12274 | Cri | 0.00 | 9.8 | 0.01 | Apr 27, 2020 | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session. | ||
| CVE-2020-8637 | Cri | 0.00 | 9.8 | 0.03 | Apr 3, 2020 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter. | ||
| CVE-2020-8841 | Hig | 0.00 | 8.8 | 0.01 | Feb 10, 2020 | An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection. |
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
- risk 0.49cvss 7.5epss 0.01
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
- risk 0.42cvss 6.5epss 0.00
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any…
- risk 0.04cvss 8.8epss 0.16
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute…
- risk 0.04cvss 7.5epss 0.06
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.
- risk 0.00cvss 7.5epss 0.01
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
- risk 0.00cvss 9.8epss 0.01
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
- risk 0.00cvss 9.8epss 0.03
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
- risk 0.00cvss 8.8epss 0.01
An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.