CVE-2019-7535

index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gurock:testrail:5.3.0.3603:*:*:*:*:*:*:*

History

21 Nov 2024, 04:48

Type Values Removed Values Added
References () https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 - Third Party Advisory () https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 - Third Party Advisory

Information

Published : 2019-02-07 16:29

Updated : 2024-11-21 04:48


NVD link : CVE-2019-7535

Mitre link : CVE-2019-7535

CVE.ORG link : CVE-2019-7535


JSON object : View

Products Affected

gurock

  • testrail
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor