VYPR

Ureport

by Ureport Project

CVEs (6)

  • CVE-2020-21125CriSep 15, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.

  • CVE-2020-21124CriSep 15, 2021
    risk 0.64cvss 9.8epss 0.02

    UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.

  • CVE-2023-24188CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

  • CVE-2023-24187HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

  • CVE-2023-48848HigNov 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path.

  • CVE-2020-21122MedSep 15, 2021
    risk 0.35cvss 5.3epss 0.01

    UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.