Описание
XML External Entity Reference in ureport
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
Пакеты
Наименование
com.bstek.ureport:ureport2-core
maven
Затронутые версииВерсия исправления
<= 2.2.9
Отсутствует
Связанные уязвимости
CVSS3: 7.8
nvd
почти 3 года назад
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.