CVE-2019-19491
MEDIUMTestLink 1.9.19 - Cross-Site Scripting via archiveData.php edit Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-19491. PoCs published by Milad Khoshdel.
AI-analyzed exploit summary This exploit demonstrates persistent and non-persistent XSS vulnerabilities in TestLink 1.9.19. The PoC includes crafted URLs and HTTP requests that trigger JavaScript execution in the context of the application.
Description
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
Exploits (1)
This exploit demonstrates persistent and non-persistent XSS vulnerabilities in TestLink 1.9.19. The PoC includes crafted URLs and HTTP requests that trigger JavaScript execution in the context of the application.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N