CVE-2019-20107
Summary
| CVE | CVE-2019-20107 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-05 13:15:00 UTC |
| Updated | 2020-03-07 01:30:00 UTC |
| Description | Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@942c406 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| 0008829: Multiple SQL Injection - MantisBT | MISC | mantis.testlink.org | Vendor Advisory |
| 0008829: Multiple SQL Injection - MantisBT | MISC | mantis.testlink.org | Vendor Advisory |
| TestLink OpenSource on Twitter: "Security Fixes: branch tl1.19.9.01 contains important SQL injection fixes for TestLink 1.9.19. Thanks to work done by people from https://t.co/TtWhl7RjNr." | MISC | twitter.com | Third Party Advisory |
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@bcf7b97 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@d27690c · GitHub | MISC | github.com | Patch, Third Party Advisory |
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@e2d88c9 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@7647a7b · GitHub | MISC | github.com | Patch, Third Party Advisory |
| fix: security #8829 · TestLinkOpenSourceTRMS/testlink-code@146b4f3 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.