S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-40875 Scanner

CVE-2021-40875 scanner - Improper Access Control vulnerability in Gurock TestRail

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40875
7.5
CVSS

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Gurock TestRail is a popular software application used by software development teams and quality assurance departments to manage and organize their testing efforts. The product offers comprehensive test case management, test planning, and reporting capabilities that help organizations streamline their testing efforts. Among its key features is the ability to manage test cases across projects and test suites, which greatly simplifies the task of tracking testing progress and results.

Recently, a vulnerability named CVE-2021-40875 was detected in Gurock TestRail versions below 7.2.0.3014. The vulnerability is a result of improper access control, where sensitive information is exposed. By gaining access to the /files.md5 file on the client side of the application, a potential attacker can expose a list of all the application files along with the corresponding file paths. This could potentially lead to the exposure of some hardcoded credentials, API keys, or other sensitive information.

The exploitation of this vulnerability can lead to some serious consequences for organizations, primarily in terms of the exposure of sensitive information. In the wrong hands, this information can be used to launch attacks on the organization or to expose other digital assets. Without adequate protection, such exploitation may result in the loss of reputation and customers, among other things.

Thanks to the pro features of s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their own digital assets. By leveraging the power of comprehensive vulnerability reports and in-depth analyses, s4e.io provides organizations with a platform to proactively identify and address vulnerabilities before they are exploited by potential attackers. This can help organizations save money, time, and most importantly, reputation. With a proactive approach to security, organizations can better protect their digital assets and maintain the trust of their customers and stakeholders.

 

REFERENCES

Solution Advice

To protect against this vulnerability, some precautions can be taken. These are: - Upgrade Gurock TestRail to version 7.2.0.3014 or later.

  • Use secure passwords and encryption to protect sensitive data.
  • Use firewalls and other security measures to limit access to critical systems and data.
  • Regularly monitor and audit access logs to identify and prevent potential unauthorized access.
  • Conduct regular security assessments to identify vulnerabilities and determine the effectiveness of existing security controls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-40875 scanner - Improper Access Control vulnerability in Gurock TestRail S4E