index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
References
Link | Resource |
---|---|
https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 | Third Party Advisory |
Configurations
Information
Published : 2019-02-07 08:29
Updated : 2019-02-08 06:01
NVD link : CVE-2019-7535
Mitre link : CVE-2019-7535
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
gurock
- testrail