Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.113670
Category:Web application abuses
Title:TestLink <= 1.9.20 Multiple Vulnerabilities
Summary:TestLink is prone to multiple vulnerabilities.
Description:Summary:
TestLink is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2020-8637: SQL injection (SQLi) in dragdroptreenodes.php via the node_id parameter

- CVE-2020-8638: SQL injection (SQLi) in planUrgency.php via the urgency parameter

- CVE-2020-8639: Arbitrary code execution due to unrestricted file uploads in keywordsImport.php

- CVE-2020-12273: A crafted login.php viewer parameter exposes cleartext credentials

- CVE-2020-12274: The lib/cfields/cfieldsExport.php goback_url parameter causes a security risk
because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the
web site associated with the session.

- CVE-2024-42906: Reflected cross-site scripting (XSS) within the file upload function.

Vulnerability Impact:
Successful exploitation would allow an attacker to gain complete
control over the target system.

Affected Software/OS:
TestLink version 1.9.20 and prior.

Solution:
No solution was made available by the vendor.

Note: Vendor states that, there is not going to be a new release and users should download the
branch testlink_1_9_20_fixed which addresses those vulnerabilities.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-8637
https://ackcent.com/blog/testlink-1.9.20-unrestricted-file-upload-and-sql-injection/
Common Vulnerability Exposure (CVE) ID: CVE-2020-8638
Common Vulnerability Exposure (CVE) ID: CVE-2020-8639
http://packetstormsecurity.com/files/161401/TestLink-1.9.20-Shell-Upload.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-12273
http://mantis.testlink.org/view.php?id=8895
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/72271ef057e6e4a95c6128973902ea646f7b5462
Common Vulnerability Exposure (CVE) ID: CVE-2020-12274
http://mantis.testlink.org/view.php?id=8894
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/2d17cd00f981f8e8c97de34a12e368ba2a55e3d0
Common Vulnerability Exposure (CVE) ID: CVE-2024-42906
CopyrightCopyright (C) 2020 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.