Ureport
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-21125 | Cri | 0.64 | 9.8 | 0.02 | Sep 15, 2021 | An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code. | ||
| CVE-2020-21124 | Cri | 0.64 | 9.8 | 0.02 | Sep 15, 2021 | UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. | ||
| CVE-2023-24188 | Cri | 0.59 | 9.1 | 0.01 | Feb 13, 2023 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | ||
| CVE-2023-24187 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile. | ||
| CVE-2023-48848 | Hig | 0.49 | 7.5 | 0.01 | Nov 28, 2023 | An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path. | ||
| CVE-2020-21122 | Med | 0.35 | 5.3 | 0.01 | Sep 15, 2021 | UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports. |
- risk 0.64cvss 9.8epss 0.02
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
- risk 0.59cvss 9.1epss 0.01
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
- risk 0.51cvss 7.8epss 0.01
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
- risk 0.49cvss 7.5epss 0.01
An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path.
- risk 0.35cvss 5.3epss 0.01
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.