Back
CVE-2020-8637
CRITICAL
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
Published: Apr 3, 2020
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| testlink | testlink | 1.9.20 |
GitHub Security Advisory GHSA-hh37-9v7m-hxg6
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL...
References (4)
- https://ackcent.com/blog/testlink-1.9.20-unrestricted-file-upload-and-sql-injection/ Exploit, Patch, Third Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/d99bd8277d384f3417e917ce20bef5d061110343 Patch, Third Party Advisory
- https://ackcent.com/blog/testlink-1.9.20-unrestricted-file-upload-and-sql-injection/ Exploit, Patch, Third Party Advisory
- https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/d99bd8277d384f3417e917ce20bef5d061110343 Patch, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.94%
Top 14% most likely to be exploited
Threat Score
40.1 / 100
Data Sources
NVD
EPSS
GitHub