Description
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
Remediation
References
http://ureport.com
https://github.com/Venus-WQLab/bug_report/blob/main/ureport/ureport-cve-2023-24188.md
https://github.com/youseries/ureport
Related Vulnerabilities
CVE-2022-45394 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2020-36732 Vulnerability in maven package org.webjars.bowergithub.brix:crypto-js
CVE-2022-0436 Vulnerability in maven package org.webjars.npm:grunt
CVE-2021-4103 Vulnerability in npm package vditor
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests