CVE-2021-36538
- EPSS 0.18%
- Veröffentlicht 03.02.2023 18:15:10
- Zuletzt bearbeitet 26.03.2025 17:15:21
Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
CVE-2021-44263
- EPSS 0.35%
- Veröffentlicht 20.12.2021 09:15:06
- Zuletzt bearbeitet 21.11.2024 06:30:41
Gurock TestRail before 7.2.4 mishandles HTML escaping.
CVE-2021-40875
- EPSS 81.11%
- Veröffentlicht 22.09.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:24:59
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application file...
CVE-2021-37788
- EPSS 0.14%
- Veröffentlicht 09.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:54
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HT...
CVE-2018-20063
- EPSS 1.57%
- Veröffentlicht 25.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:49
An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an...
CVE-2019-7535
- EPSS 0.23%
- Veröffentlicht 07.02.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:17
index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
CVE-2014-4857
- EPSS 0.61%
- Veröffentlicht 26.07.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.