CVE-2020-12273: High severity testlink vulnerability
Published Apr 27, 2020
·Updated
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Remediation
Event History
Apr 27, 2020
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12273?
CVE-2020-12273 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-12273?
To fix CVE-2020-12273, upgrade TestLink to version 1.9.21 or later.
3
What type of vulnerability is CVE-2020-12273?
CVE-2020-12273 is an information disclosure vulnerability that exposes cleartext credentials.
4
What software versions are affected by CVE-2020-12273?
Only TestLink version 1.9.20 is affected by CVE-2020-12273.
5
What impact does CVE-2020-12273 have on users?
CVE-2020-12273 can allow unauthorized users to gain access to sensitive user credentials.