reportico-web/reportico

reportico-web/reportico

Releases79
Frequency1 month 1 week
Last Release
Stars171
Reportico Open Source PHP report Designer

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH

An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

6.5 MEDIUM

An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

6.5 MEDIUM

SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.

4.8 MEDIUM

Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).