CVE-2018-7668: Testlink

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.

Affected products

  • Testlink Testlink: up to and including 1.9.16

Published 2018-03-05. Last modified 2026-06-17.