CVE-2020-8841: SQL Injection
Published Feb 10, 2020
·Updated
An issue was discovered in TestLink 1.9.19. The relationtype parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.
Affected Software
1 affected component
TestLink TestLink=1.9.19
Event History
Feb 10, 2020
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description
Data Sourced
via NVD·09:56 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8841?
CVE-2020-8841 is considered high severity due to its potential for authenticated SQL Injection.
2
How do I fix CVE-2020-8841?
To fix CVE-2020-8841, update TestLink to a version that addresses this vulnerability.
3
What software is affected by CVE-2020-8841?
CVE-2020-8841 affects TestLink version 1.9.19.
4
Can CVE-2020-8841 be exploited remotely?
No, CVE-2020-8841 requires authenticated access to exploit the SQL Injection vulnerability.
5
What parameters are involved in CVE-2020-8841?
The relation_type parameter of the lib/requirements/reqSearch.php endpoint is specifically involved in CVE-2020-8841.