{"api_version":"1","generated_at":"2026-07-23T16:50:45+00:00","cve":"CVE-2021-36538","urls":{"html":"https://cve.report/CVE-2021-36538","api":"https://cve.report/api/cve/CVE-2021-36538.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36538","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36538"},"summary":{"title":"CVE-2021-36538","description":"Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-02-03 18:15:00","updated_at":"2023-02-09 18:53:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab","name":"https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab","refsource":"MISC","tags":[],"title":"Stored Cross-site scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows an authenticated threat actors to inject arbitrary web script or HTML via the reference field in milestones or description fields in reports. · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36538","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36538","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"36538","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gurock","cpe5":"testrail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-36538","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab","refsource":"MISC","name":"https://gist.github.com/miglen/b09498b4b9fe1be58973bd474af125ab"}]},"impact":{"cvss":{"attackComplexity":"LOW","availabilityImpact":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AC:L/A:N/A:H/C:N/C:H/I:N/I:H/PR:N/PR:L/S:U/S:C/UI:N/UI:R","version":"3.1"}}},"nvd":{"publishedDate":"2023-02-03 18:15:00","lastModifiedDate":"2023-02-09 18:53:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gurock:testrail:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36538","Ordinal":"212088","Title":"CVE-2021-36538","CVE":"CVE-2021-36538","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36538","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}