Showing 1 vulnerability on this page for testrail

Signals CISA KEV Ransomware Nuclei
gurock vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

gurock testrail Direct Request ('Forced Browsing')

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CWE-425CWE-863Sep 22, 20211 related artifact
CVSS7.5v3.1EPSS48.4%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX