← Vulnerability feed

Vulnerability record · CVE-2022-35196 · published 20 September 2022

CVE-2022-35196: Testlink cross-site request forgery vulnerability

Testlink · Testlink

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

8.8 CVSS 3.1 High EPSS 0.50% · top 59.5% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-35196 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6006Testlink improper authentication vulnerabilityTestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.EPSS 1.4%9.8CVE-2020-12274Testlink vulnerabilityIn TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not const…EPSS 1.2%9.8CVE-2020-8637Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id paramete…EPSS 2.9%9.8CVE-2020-8638Testlink sql injection vulnerabilityA SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.EPSS 1.7%9.8CVE-2015-7390Testlink sql injection vulnerabilitySQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.EPSS 1.6%9.0CVE-2014-5308Testlink sql injection vulnerabilityMultiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name paramet…EPSS 3.5%8.8CVE-2020-8639Testlink unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a f…EPSS 16%8.8CVE-2019-20107Testlink sql injection vulnerabilityMultiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tpr…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2022-35196), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.