CVE-2021-47760: TestLink 1.19 - Arbitrary File Download (Unauthenticated)
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.
Affected Software
1 affected component
TestLink TestLink>=1.16<=1.19
Event History
Jan 15, 2026
CVE Published
via MITRE·03:52 PM
Rejected
via MITRE·03:52 PM
Data Sourced
via NVD·04:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·08:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-47760?
CVE-2021-47760 has a high severity rating as it allows unauthenticated attackers to exploit the vulnerability to download arbitrary files.
2
How do I fix CVE-2021-47760?
To fix CVE-2021-47760, upgrade TestLink to a version later than 1.19 that addresses this file download vulnerability.
3
What versions of TestLink are affected by CVE-2021-47760?
TestLink versions 1.16 through 1.19 are affected by CVE-2021-47760.
4
Can attackers exploit CVE-2021-47760 without authentication?
Yes, attackers can exploit CVE-2021-47760 without any authentication, making it particularly dangerous.
5
What is the exploit method for CVE-2021-47760?
The exploit method for CVE-2021-47760 involves using the 'id' parameter in the attachmentdownload.php endpoint with 'skipCheck=1' to iterate file IDs.