Gurock
Gurock Testrail: vulnerabilidades y CVE
Gurock Testrail tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-36538 | Media (5.4) | 0.55% | — | 3 feb 2023 | Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports. |
| CVE-2021-44263 | Media (5.4) | 0.59% | — | 20 dic 2021 | Gurock TestRail before 7.2.4 mishandles HTML escaping. |
| CVE-2021-40875 | Alta (7.5) | 47% | — | 22 sept 2021 | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing… |
| CVE-2021-37788 | Media (5.4) | 1.5% | — | 9 ago 2021 | A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input… |
| CVE-2018-20063 | Alta (8.8) | 2.7% | — | 25 feb 2019 | An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute… |
| CVE-2019-7535 | Media (5.3) | 1.1% | — | 7 feb 2019 | index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology. |
| CVE-2014-4857 | Media (4.3) | 1.7% | — | 26 jul 2014 | Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity. |