CVE-2021-44263 Information

Description

Gurock TestRail before 7.2.4 mishandles HTML escaping.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://discuss.gurock.com/t/testrail-7-2-4-released-to-cloud/20248 https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: