CVE-2021-40875 describes an improper access control vulnerability in Gurock TestRail versions prior to 7.2.0.3014. This flaw allows an unauthenticated attacker to access the /files.md5 file, revealing a complete list of application files and their paths. This exposure can lead to the discovery of hardcoded credentials, API keys, or other sensitive data. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating that it can be exploited remotely with low complexity and without user interaction, resulting in high confidentiality impact. Its EPSS score of 0.68736 also suggests a higher-than-average likelihood of exploitation. While not listed on the CISA KEV catalog or the Hot List, public exploit code is available via ExploitDB and Nuclei templates, indicating a readily exploitable condition. Despite this, there is currently no evidence of active exploitation, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.0.3014CPE matchmatch criteria | cpe:2.3:a:gurock:testrail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.