Vulnerabilities > CVE-2020-12274 - Unspecified vulnerability in Testlink 1.9.20
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |