CVE-2018-16987: Squashtest Squash TM

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.

Affected products

Published 2018-09-13. Last modified 2026-06-17.