CVE-2020-12274: Critical severity testlink vulnerability
Published Apr 27, 2020
·Updated
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php gobackurl parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Remediation
Event History
Apr 27, 2020
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12274?
CVE-2020-12274 is considered a medium severity vulnerability due to its exploitation potential based on user input.
2
How do I fix CVE-2020-12274?
To address CVE-2020-12274, ensure that the goback_url parameter is properly validated and sanitized to prevent unauthorized redirects.
3
What software versions are affected by CVE-2020-12274?
CVE-2020-12274 affects TestLink version 1.9.20.
4
What type of vulnerability is CVE-2020-12274?
CVE-2020-12274 is classified as an open redirect vulnerability.
5
Is CVE-2020-12274 exploitable remotely?
Yes, CVE-2020-12274 can be exploited remotely by manipulating the goback_url parameter in requests.