PT-2019-18631 · Gurock · Gurock Testrail

Nenf

·

Published

2019-02-07

·

Updated

2019-02-08

·

CVE-2019-7535

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gurock TestRail version 5.3.0.3603
Description The issue concerns the disclosure of potentially sensitive information when an invalid request is made to index.php. This can lead to full path disclosure and the identification of PHP as the backend technology.
Recommendations For Gurock TestRail version 5.3.0.3603, consider updating to a newer version that addresses this issue, as the current version may disclose sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7535

Affected Products

Gurock Testrail