Skip to main content

Vendor/product archive

gurock / testrail CVEs

Beta · best-effort

7 CVEs tagged to gurock / testrail0 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2021-36538

Published Feb 3, 2023

Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or descr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40875

Published Sep 22, 2021

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37788

Published Aug 9, 2021

A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vul…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20063

Published Feb 25, 2019

An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7535

Published Feb 7, 2019

index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4857

Published Jul 26, 2014

Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1