Vulnerabilities
17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-48848 | An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path. An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-24187 | An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/sa An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile. NVD description · AI analysis pending | 7.8 | <1% | PoC ×2 |
| — | |
| CVE-2023-24188 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. NVD description · AI analysis pending | 9.1 | 1% | PoC |
| — | |
| CVE-2022-23052 | PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application. NVD description · AI analysis pending | 6.5 group max | <1% | PoC ×2 |
| — | |
| CVE-2020-21124 | UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2021-21275 | The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2019-25012 | The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2020-15885 | A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by po A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-15884 +1 in the same advisory: …15882 | A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on PO A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2020-10190 | An issue was discovered in MunkiReport before 5.3.0. An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables/data endpoint. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — |