vendor:
TestLink
by:
High-Tech Bridge Security Research Lab
5.1
CVSS
MEDIUM
Cross-Site Request Forgery [CWE-352]
352
CWE
Product Name: TestLink
Affected Version From: 1.9.2003
Affected Version To: 1.9.2003
Patch Exists: YES
Related CWE: CVE-2012-2275
CPE: testlink
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
?ross-Site Request Forgery (CSRF) in TestLink: CVE-2012-2275
The application allows authorized users to perform certain actions via HTTP requests without making proper validity checks to verify the source of the requests. This can be exploited to add, delete or modify sensitive information, for example to change administrator's email. An attacker should make logged-in administrator open a malicious link in the browser to exploit this vulnerability.
Mitigation:
Upgrade to TestLink 1.9.4