Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2p54-q56g-9668

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.8

Описание

TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls.

TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls.

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

nvd
23 дня назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639