CVE-2020-8638: SQL Injection
Published Apr 3, 2020
·Updated
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Remediation
Event History
Apr 3, 2020
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8638?
CVE-2020-8638 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2020-8638?
To fix CVE-2020-8638, upgrade TestLink to a version that addresses the SQL injection issue.
3
What type of vulnerability is CVE-2020-8638?
CVE-2020-8638 is a SQL injection vulnerability that allows arbitrary SQL command execution.
4
Which version of TestLink is affected by CVE-2020-8638?
CVE-2020-8638 affects TestLink version 1.9.20.
5
Can CVE-2020-8638 lead to data loss?
Yes, CVE-2020-8638 can potentially lead to data loss or unauthorized access to sensitive information.