youseries/ureport

youseries/ureport

Releases9
Frequency4 weeks 2 days
Last Release
Stars2.16K
UReport2 is a high-performance pure Java report engine based on Spring architecture, where complex Chinese-style statements and reports can be prepared by iterating over cells.

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH

An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

9.1 CRITICAL

ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

5.3 MEDIUM5 MEDIUM

UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

9.8 CRITICAL7.5 HIGH

UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.

9.8 CRITICAL7.5 HIGH

An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.