Information ================================= Name: Persistent XSS Vulnerability in TestLink 1.9.14 Affected Software: TestLink Affected Versions: 1.9.14 and possibly below Vendor Homepage: http://testlink.org/ Severity: High Status: Fixed Vulnerability Type: ================================= Persistent XSS CVE Reference: ================================= Not assigned Technical Details: ================================= Persistent XSS entry point exist in TestLink 1.9.14 allowing arbitrary client side browser code execution on victims who visit persistently stored XSS payloads. The vulnerability has been discovered in the POST request to create a new Test Project. By exploiting the vulnerability, the attacker will get access to the logged in users session cookie. No Filtering exist on the vulnerable parameter. Vulnerable Parameter: ================================= notes Exploit Code =================================