> CVE-2021-40875: Improper Access Control in Gurock TestRail versions ≤ 7.2.0.3014 results in sensitive file exposure
[DATE: 22/09/2021 06:00]
[LANGUAGE: EN]
Credits John Github: https://github.com/johnjhacking
SickCodes
Twitter: https://twitter.com/sickcodes
Identification During research, I stumbled upon a TestRail application. While using Burp Suite to look at various requests and responses of the application, I noticed a files.md5 path:
It seemed fairly normal at first, until I saw how massive the list was:
I attempted to try some of the paths, and was forbidden from accessing a lot of them. When I found a few paths that worked, I realized that I would need a better solution to check all of the paths.