← Vulnerability feed

Vulnerability record · CVE-2019-20107 · published 5 March 2020

CVE-2019-20107: Testlink sql injection vulnerability

Testlink · Testlink

Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration.

8.8 CVSS 3.1 High EPSS 2.0% · top 20.5% CWE-89 · SQL injection
8.8CVSS 3.1 base score, v2 6.5
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://mantis.testlink.org/view.php?id=8829 Vendor Advisory
http://mantis.testlink.org/view.php?id=8829#c29360 Vendor Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/146b4f38010a48c36b7d9650060ca354c92ab4ac PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/7647a7b53ceab31524cfcfb3beb8435af0a30fc1 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/942c406fcee5d376235a264cb8a79300a0002d20 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/bcf7b971b5c88ea08d2dc47685f319be3b02cea8 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/d27690c6cb7708a6db0701b6428381d32d51495a PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/e2d88c9d7f8e02640ba65e5ff74b55d0399a53d0 PatchThird Party Advisory
https://twitter.com/TLOpenSource/status/1212394020946751489 Third Party Advisory
http://mantis.testlink.org/view.php?id=8829 Vendor Advisory
http://mantis.testlink.org/view.php?id=8829#c29360 Vendor Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/146b4f38010a48c36b7d9650060ca354c92ab4ac PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/7647a7b53ceab31524cfcfb3beb8435af0a30fc1 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/942c406fcee5d376235a264cb8a79300a0002d20 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/bcf7b971b5c88ea08d2dc47685f319be3b02cea8 PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/d27690c6cb7708a6db0701b6428381d32d51495a PatchThird Party Advisory
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/e2d88c9d7f8e02640ba65e5ff74b55d0399a53d0 PatchThird Party Advisory
https://twitter.com/TLOpenSource/status/1212394020946751489 Third Party Advisory

Track CVE-2019-20107 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6006Testlink improper authentication vulnerabilityTestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.EPSS 1.4%9.8CVE-2020-12274Testlink vulnerabilityIn TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not const…EPSS 1.2%9.8CVE-2020-8637Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id paramete…EPSS 2.9%9.8CVE-2020-8638Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.EPSS 1.7%9.8CVE-2015-7390Testlink sql injection vulnerabilitySQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.EPSS 1.6%9.0CVE-2014-5308Testlink sql injection vulnerabilityMultiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name paramet…EPSS 3.5%8.8CVE-2022-35196Testlink cross-site request forgery vulnerabilityTestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.EPSS 0.50%8.8CVE-2020-8639Testlink unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2019-20107), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.