8.8

CVE-2020-8639

Exploit
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TestlinkTestlink Version1.9.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.86% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://ackcent.com/blog/testlink-1.9.20-unrestricted-file-upload-and-sql-injection/
Patch
Third Party Advisory
Exploit
http://packetstormsecurity.com/files/161401/TestLink-1.9.20-Shell-Upload.html
Third Party Advisory
Exploit
VDB Entry
https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/57d81ae350d569c5c95087997fe051c49e14516d
Patch
Third Party Advisory