An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.
References
Link | Resource |
---|---|
https://github.com/TestLinkOpenSourceTRMS/testlink-code/pull/239 | Exploit Third Party Advisory |
https://github.com/ver007/testlink-1.9.19-sqlinject | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-02-10 21:56
Updated : 2024-02-04 20:39
NVD link : CVE-2020-8841
Mitre link : CVE-2020-8841
CVE.ORG link : CVE-2020-8841
JSON object : View
Products Affected
testlink
- testlink
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')