Gurock Software GmbH Information for VU#669804
TestRail cross-site scripting vulnerability
- Vendor Information Help Date Notified: 18 Jul 2014
- Statement Date:
- Date Updated: 24 Jul 2014
All TestRail Hosted accounts (the cloud/SaaS edition of TestRail) have already been updated automatically by the vendor. All TestRail on-premise customers can download the new version from the customer portal and follow the upgrade instructions as usual.
The vulnerability can only be taken advantage of by actual users with existing TestRail access. Persons without access to TestRail cannot inject any code using this vulnerability or access any information or data without permissions.
We are not aware of further vendor information regarding this vulnerability.
There are no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.