Impact
The vulnerability is an authenticated Insecure Direct Object Reference in TestLink 1.9.20 and earlier, allowing any authenticated user, even those with low‑privilege guest accounts, to download any attachment by supplying an integer attachment ID to attachmentdownload.php. This bypasses the per‑project access controls and exposes files containing test specifications, requirements, execution evidence, and other sensitive data. The primary effect is the disclosure of confidential information.
Affected Systems
The affected product is TestLinkOpenSourceTRMS:TestLink, versions 1.9.20 and all earlier releases. Any installation of these versions running attachmentdownload.php is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact vulnerability. The EPSS score is not provided, and it is not listed in the CISA KEV catalog. The attack vector is a web‑based IDOR that requires initial authentication but otherwise imposes no additional preconditions. An attacker can enumerate sequential attachment IDs and retrieve files from private projects the attacker has no membership in, making exploitation straightforward for any logged‑in user.
OpenCVE Enrichment