An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.
{
"cpe": "cpe:2.3:a:testlink:testlink:1.9.19:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.9.19"
},
{
"last_affected": "1.9.19"
}
],
"source": "CPE_STRING"
}