PT-2020-13086 · Testlink · Testlink
CVE-2020-12273
·
Published
2020-04-27
·
Updated
2021-07-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TestLink version 1.9.20
Description
A crafted
viewer parameter in the login.php endpoint exposes cleartext credentials.Recommendations
For TestLink version 1.9.20, avoid using the
viewer parameter in the login.php endpoint until the issue is resolved.Exploit
Fix
Insufficiently Protected Credentials
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Testlink