CVE-2015-7390: SQL Injection
Published Sep 26, 2017
·Updated
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
Affected Software
1 affected component
TestLink TestLink<=1.9.13
Event History
Sep 26, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7390?
CVE-2015-7390 is rated as a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2015-7390?
To fix CVE-2015-7390, upgrade TestLink to version 1.9.14 or later.
3
Which versions of TestLink are affected by CVE-2015-7390?
TestLink versions prior to 1.9.14, specifically including 1.9.13 and earlier, are affected by CVE-2015-7390.
4
What type of attack does CVE-2015-7390 enable?
CVE-2015-7390 enables remote SQL injection attacks through the apikey parameter in lnl.php.
5
Can CVE-2015-7390 be exploited without authentication?
Yes, CVE-2015-7390 can be exploited by unauthenticated remote attackers.