CVE-2024-42906: XSS
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42906?
CVE-2024-42906 is classified as a medium severity vulnerability due to its potential for Cross Site Scripting (XSS) exploitation.
How do I fix CVE-2024-42906?
To fix CVE-2024-42906, upgrade TestLink to version 1.9.20 or later, which addresses the XSS vulnerability.
What types of attacks can exploit CVE-2024-42906?
CVE-2024-42906 can be exploited through Cross Site Scripting (XSS) attacks by injecting malicious scripts via the file upload feature.
Is my version of TestLink vulnerable to CVE-2024-42906?
If you are using a version of TestLink prior to 1.9.20, your installation is vulnerable to CVE-2024-42906.
What are the potential impacts of CVE-2024-42906?
The potential impacts of CVE-2024-42906 include unauthorized access to user sessions and manipulation of sensitive data due to XSS attacks.