Ureport2 ProjectCVEs & Vulnerabilities
2 CVEs affecting Ureport2 Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
ureport2 2
CVE-2023-50090CRITICAL
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
3 Jan 2024
9.8
CVSS
CVE-2022-25767CRITICAL
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
1 May 2022
9.8
CVSS
← PrevPage 1 / 1Next →