Количество 2
Количество 2
CVE-2021-47760
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.
GHSA-2p54-q56g-9668
TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-47760 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate. | 24 дня назад | |||
GHSA-2p54-q56g-9668 TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls. | CVSS3: 9.8 | 24 дня назад |
Уязвимостей на страницу