CVE-2020-8639
03.04.2020, 19:15
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.Enginsight
Vendor | Product | Version |
---|---|---|
testlink | testlink | 1.9.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References