Vulnerability Description
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Testlink | Testlink | < 1.9.20 |
Related Weaknesses (CWE)
References
- http://mantis.testlink.org/view.php?id=8808Issue TrackingThird Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/cde692895e425731ePatchThird Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/compare/1.9.19...1.9.20Third Party Advisory
- http://mantis.testlink.org/view.php?id=8808Issue TrackingThird Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/cde692895e425731ePatchThird Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/compare/1.9.19...1.9.20Third Party Advisory
FAQ
What is CVE-2019-20381?
CVE-2019-20381 is a vulnerability with a CVSS score of 6.1 (MEDIUM). TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
How severe is CVE-2019-20381?
CVE-2019-20381 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20381?
Check the references section above for vendor advisories and patch information. Affected products include: Testlink Testlink.