CVE-2019-19491: XSS
Published Dec 2, 2019
·Updated
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
Affected Software
1 affected component
TestLink TestLink=1.9.19
Event History
Dec 2, 2019
CVE Published
via MITRE·01:13 AM
Data Sourced
via MITRE·01:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19491?
CVE-2019-19491 has a medium severity rating due to its potential for XSS attacks.
2
How do I fix CVE-2019-19491?
To fix CVE-2019-19491, upgrade to a version of TestLink that is not affected by the vulnerability.
3
What are the affected software versions for CVE-2019-19491?
CVE-2019-19491 affects TestLink 1.9.19 specifically.
4
What type of vulnerability is CVE-2019-19491?
CVE-2019-19491 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
How can CVE-2019-19491 be exploited?
CVE-2019-19491 can be exploited by injecting malicious scripts into the affected parameters, potentially affecting users who access those links.