PT-2026-69101 · Testlink · Testlink
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TestLink versions prior to 1.9.21
Description
An insecure direct object reference (IDOR) exists where authenticated users, including those with low-privilege guest accounts, can read arbitrary attachments. By providing an integer attachment ID to the 'attachmentdownload.php' endpoint, an attacker can bypass project and role authorization checks. This allows the enumeration of sequential IDs to retrieve sensitive files, such as test specifications, requirements documents, and execution evidence, from private projects regardless of the user's membership.
Recommendations
Update TestLink to a version newer than 1.9.20.
As a temporary mitigation, restrict access to the 'attachmentdownload.php' handler.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Testlink