TestRail Installation Wizard
TestRail is susceptible to the Installation page exposure due to misconfiguration.
testrailPoC 已收录
CVSS—
共找到 2 条公开漏洞记录
TestRail is susceptible to the Installation page exposure due to misconfiguration.
Improper access control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths which can then be tested, and in some cases result in the disclosure of hardcoded credentials, API keys, or other sensitive data.