Vulnerabilities > Ureport Project > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-02-13 CVE-2023-24188 Path Traversal vulnerability in Ureport Project Ureport 2.2.9
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
network
low complexity
ureport-project CWE-22
critical
9.1
2021-09-15 CVE-2020-21124 Incorrect Authorization vulnerability in Ureport Project Ureport 2.2.9
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
network
low complexity
ureport-project CWE-863
critical
9.8
2021-09-15 CVE-2020-21125 Unspecified vulnerability in Ureport Project Ureport 2.2.9
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
network
low complexity
ureport-project
critical
9.8