CVE-2020-8637: SQL Injection
Published Apr 3, 2020
·Updated
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the nodeid parameter.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Remediation
Event History
Apr 3, 2020
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8637?
CVE-2020-8637 is classified as a critical vulnerability due to its potential for executing arbitrary SQL commands.
2
How do I fix CVE-2020-8637?
To mitigate CVE-2020-8637, upgrade TestLink to the latest version that addresses this SQL injection vulnerability.
3
What software is affected by CVE-2020-8637?
CVE-2020-8637 affects TestLink version 1.9.20.
4
Can CVE-2020-8637 be exploited remotely?
Yes, CVE-2020-8637 can be exploited remotely if attackers manipulate the node_id parameter in the dragdroptreenodes.php file.
5
What type of vulnerability is CVE-2020-8637?
CVE-2020-8637 is a SQL injection vulnerability that allows for arbitrary SQL command execution.