(#Several vulnerabilities were reported in TestLink:#- CVE-2015-7390: SQL injection SQL exploitable via the "apike" parameter of the "lnl.php" web page#- CVE-2015-7391: multiple cross-site scripting vulnerabilities##Proofs of concept are available.)
Vulnerable Products
Vulnerable Software: TestLink (TestLink) - 1.9.13
Solution
Version 1.9.14 of TestLink fixes these vulnerabilities.