Fiche vulnérabilité
CVE-2023-50090 : faille critique ureport2 project ureport2 (CVSS 9.8)
Description
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 3 janv. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ureport2 project ureport2