CVE-2018-20063

HIGH

Gurock TestRail 5.6.0.3853 - Unrestricted Upload of File

Title source: llm
STIX 2.1

Description

An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an executable extension but a safe Content-Type value, and then accessing it via a direct request to the file in the file-upload directory (if it's accessible according to the server configuration).

Scores

CVSS v3 8.8
EPSS 0.0157
EPSS Percentile 81.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
gurock/testrail 5.6.0.3853
Published Feb 25, 2019
Tracked Since Feb 18, 2026