CVE-2018-7466: Testlink

High severity, CVSS 7.5. EPSS: 6.1% chance of exploitation in the next 30 days.

install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.

Affected products

  • Testlink Testlink: up to and including 1.9.16

Published 2018-02-25. Last modified 2026-06-17.