Arbitrary Code Execution via Cross Site Scripting (XSS) in Gurock TestRail
CVE-2021-36538 · MEDIUM Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
Learn more about our Web Application Penetration Testing UK.