CVE-2022-35194: XSS
Published Sep 16, 2022
·Updated
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Event History
Sep 16, 2022
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35194?
CVE-2022-35194 is classified as a medium severity vulnerability due to its potential impact on user data and session integrity.
2
How do I fix CVE-2022-35194?
To fix CVE-2022-35194, you should update TestLink to version 1.9.21 or later, which addresses the stored XSS vulnerability.
3
What is the impact of CVE-2022-35194?
The impact of CVE-2022-35194 includes possible malicious script execution in the browser of users, leading to data theft or session hijacking.
4
Which versions of TestLink are affected by CVE-2022-35194?
CVE-2022-35194 affects TestLink version 1.9.20 specifically.
5
Where does CVE-2022-35194 occur in TestLink?
CVE-2022-35194 occurs in the /lib/inventory/inventoryView.php file of TestLink.