PT-2009-6399 · Testlink Team · Testlink

CVE-2009-4237

·

Publicado

2009-12-10

·

Atualizado

2024-02-14

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TestLink versions prior to 1.8.5
Description The issue allows remote attackers to inject arbitrary web script or HTML via several parameters, including the req parameter to "login.php", and allows remote authenticated users to inject arbitrary web script or HTML via parameters such as key to "lib/general/staticPage.php", tableName to "lib/attachments/attachmentupload.php", startDate, endDate, or logLevel to "lib/events/eventviewer.php", search notes string to "lib/results/resultsMoreBuilds buildReport.php", and expected results, name, steps, or summary in a find action to "lib/testcases/searchData.php".
Recommendations For versions prior to 1.8.5, update to version 1.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable parameters, such as req, key, tableName, startDate, endDate, logLevel, search notes string, expected results, name, steps, and summary, until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4237

Produtos afetados

Testlink