CVE-2018-7668: Testlink
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
Affected products
- Testlink Testlink: up to and including 1.9.16
Published 2018-03-05. Last modified 2026-06-17.