CVE-2022-35196: CSRF
Published Sep 20, 2022
·Updated
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
Affected Software
1 affected component
TestLink TestLink=1.9.20
Event History
Sep 20, 2022
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35196?
CVE-2022-35196 has a medium severity rating due to its potential for exploitation through Cross-Site Request Forgery.
2
How do I fix CVE-2022-35196?
To fix CVE-2022-35196, update TestLink to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2022-35196?
CVE-2022-35196 specifically affects TestLink version 1.9.20.
4
What is Cross-Site Request Forgery in CVE-2022-35196?
In the context of CVE-2022-35196, Cross-Site Request Forgery allows an attacker to execute unauthorized commands on behalf of an authenticated user.
5
How can I determine if my installation is vulnerable to CVE-2022-35196?
You can determine if your installation is vulnerable to CVE-2022-35196 by checking if you are using TestLink version 1.9.20.