This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor ureport2 Project First view 2022-05-01
Product ureport2 Last view 2024-01-03
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:ureport2_project:ureport2

Activity : Overall

Related : CVE

  Date Alert Description
9.8 2024-01-03 CVE-2023-50090

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.

9.8 2022-05-01 CVE-2022-25767

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-502 Deserialization of Untrusted Data