CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an executable extension but a safe Content-Type value, and then accessing it via a direct request to the file in the file-upload directory (if it's accessible according to the server configuration).
Related CVEs
Other vulnerabilities affecting the same vendor(s)