← Back

CVE-2018-20063

nvd nist
Published: Feb 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an executable extension but a safe Content-Type value, and then accessing it via a direct request to the file in the file-upload directory (if it's accessible according to the server configuration).

Affected (1)

Products: Gurock: Testrail
1 product
Testrail
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.6.0.3853

Timeline

No history available yet.