Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
References
Link Resource
https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-02-03T00:00:00

Updated: 2023-02-03T00:00:00

Reserved: 2021-07-12T00:00:00


Link: CVE-2021-36538

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-02-03T18:15:10.760

Modified: 2023-02-09T18:53:01.743


Link: CVE-2021-36538

JSON object: View

cve-icon Redhat Information

No data.

CWE