vendor:
TestLink
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: TestLink
Affected Version From: 1.8.2005
Affected Version To: 1.8.2005
Patch Exists: NO
Related CWE:
CPE: testlink
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerability in TestLink
An attacker can execute arbitrary script code in the browser of an unsuspecting user by exploiting the lack of proper input sanitization in TestLink. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
Ensure proper input validation and sanitization to prevent XSS attacks. Update TestLink to a patched version if available.