CVE-2018-7668: Infoleak
Published Mar 5, 2018
·Updated
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
Affected Software
1 affected component
TestLink TestLink<=1.9.16
Remediation
Patch Available
Event History
Mar 5, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7668?
The severity of CVE-2018-7668 is considered medium as it allows unauthorized access to sensitive attachments.
2
How do I fix CVE-2018-7668?
To fix CVE-2018-7668, upgrade to a version of TestLink higher than 1.9.16.
3
What are the consequences of exploiting CVE-2018-7668?
Exploiting CVE-2018-7668 can lead to unauthorized access to arbitrary attachments stored in the TestLink application.
4
Which versions of TestLink are affected by CVE-2018-7668?
TestLink versions up to and including 1.9.16 are affected by CVE-2018-7668.
5
What type of attack does CVE-2018-7668 enable?
CVE-2018-7668 enables remote attackers to perform unauthorized reading of attachments by manipulating the ID field.