Arbitrary Code Execution via Cross Site Scripting (XSS) in Gurock TestRail

Arbitrary Code Execution via Cross Site Scripting (XSS) in Gurock TestRail

CVE-2021-36538 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.

Learn more about our Web Application Penetration Testing UK.