← Vulnerability feed

Vulnerability record · CVE-2020-12274 · published 27 April 2020

CVE-2020-12274: Testlink vulnerability

Testlink · Testlink

In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.

9.8 CVSS 3.1 Critical EPSS 1.2% · top 32.3%
9.8CVSS 3.1 base score, v2 7.5
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12274 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6006Testlink improper authentication vulnerabilityTestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.EPSS 1.4%9.8CVE-2020-8637Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id paramete…EPSS 2.9%9.8CVE-2020-8638Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.EPSS 1.7%9.8CVE-2015-7390Testlink sql injection vulnerabilitySQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.EPSS 1.6%9.0CVE-2014-5308Testlink sql injection vulnerabilityMultiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name paramet…EPSS 3.5%8.8CVE-2022-35196Testlink cross-site request forgery vulnerabilityTestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.EPSS 0.50%8.8CVE-2020-8639Testlink unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f…EPSS 16%8.8CVE-2019-20107Testlink sql injection vulnerabilityMultiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tpr…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2020-12274), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.