TestLink contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program fails to properly restrict access to audit logs, which will disclose session identifier information to a remote attacker.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability.