CVE-2019-20381

Publication date

2020-01-20 05:21:28

Family

mitre

State

PUBLISHED

Description

TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.