Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
References
Link | Resource |
---|---|
https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab | Exploit Third Party Advisory |
https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab - Exploit, Third Party Advisory |
Information
Published : 2023-02-03 18:15
Updated : 2024-11-21 06:13
NVD link : CVE-2021-36538
Mitre link : CVE-2021-36538
CVE.ORG link : CVE-2021-36538
JSON object : View
Products Affected
gurock
- testrail
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')