Vulnerabilities > Ureport2 Project

DATE CVE VULNERABILITY TITLE RISK
2024-01-03 CVE-2023-50090 Unspecified vulnerability in Ureport2 Project Ureport2
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
network
low complexity
ureport2-project
critical
9.8
2022-05-01 CVE-2022-25767 Deserialization of Untrusted Data vulnerability in Ureport2 Project Ureport2
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
network
low complexity
ureport2-project CWE-502
critical
9.8