Gurock

Testrail

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 03.02.2023 18:15:10
  • Zuletzt bearbeitet 26.03.2025 17:15:21

Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 20.12.2021 09:15:06
  • Zuletzt bearbeitet 21.11.2024 06:30:41

Gurock TestRail before 7.2.4 mishandles HTML escaping.

Exploit
  • EPSS 81.11%
  • Veröffentlicht 22.09.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:24:59

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application file...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 09.08.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:15:54

A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HT...

  • EPSS 1.57%
  • Veröffentlicht 25.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:49

An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an...

  • EPSS 0.23%
  • Veröffentlicht 07.02.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:48:17

index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.

  • EPSS 0.61%
  • Veröffentlicht 26.07.2014 15:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.