📦 Ureport

by Ureport Project

🔍 What is Ureport?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24188

CRITICAL CVSS 9.1 Feb 13, 2023

CVE-2023-24188 is a directory traversal vulnerability in ureport v2.2.9 that allows attackers to delete arbitrary files on the server by exploiting the deletion function. This affects all systems runn...

CVE-2020-21124

CRITICAL CVSS 9.8 Sep 15, 2021

CVE-2020-21124 is a critical access control vulnerability in UReport 2.2.9 that allows attackers to reach the designer page without authentication, leading to arbitrary code execution. This affects al...

CVE-2023-48848

HIGH CVSS 7.5 Nov 28, 2023

CVE-2023-48848 is an arbitrary file read vulnerability in ureport v2.2.9 that allows remote attackers to read sensitive files on the server by manipulating file paths. This affects systems running vul...

CVE-2023-24187

HIGH CVSS 7.8 Feb 14, 2023

This XXE vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code by uploading a specially crafted XML file to the /ureport/designer/saveReportFile endpoint. Attackers can potentiall...