index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
References
Link | Resource |
---|---|
https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-07 16:29
Updated : 2024-02-04 20:03
NVD link : CVE-2019-7535
Mitre link : CVE-2019-7535
CVE.ORG link : CVE-2019-7535
JSON object : View
Products Affected
gurock
- testrail
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor