Review reviewHigh
CVE-2023-24187
ureport
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
- CVSS
- 7.8
- EPSS
- 0.92% 56.8% percentile
- CISA KEV
- Not listed
- Published
- 2023.02.14