CVE-2021-44263
Summary
| CVE | CVE-2021-44263 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-20 09:15:00 UTC |
| Updated | 2022-07-28 18:00:00 UTC |
| Description | Gurock TestRail before 7.2.4 mishandles HTML escaping. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stored Cross-site scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows an authenticated threat actors to inject arbitrary web script or HTML via the reference field in milestones or description fields in reports. · GitHub | MISC | gist.github.com | |
| TestRail 7.2.4 Released to Cloud - TestRail News - TestRail Community & Forum | CONFIRM | discuss.gurock.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.