Gurock TestRail before 7.2.4 mishandles HTML escaping.
References
Link | Resource |
---|---|
https://discuss.gurock.com/t/testrail-7-2-4-released-to-cloud/20248 | Release Notes Vendor Advisory |
https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-12-20 01:15
Updated : 2022-07-28 11:00
NVD link : CVE-2021-44263
Mitre link : CVE-2021-44263
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
gurock
- testrail