Description
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
Remediation
References
http://ureport.com
https://github.com/Venus-WQLab/bug_report/blob/main/ureport/ureport-cve-2023-24188.md
https://github.com/youseries/ureport
Related Vulnerabilities
CVE-2022-1330 Vulnerability in npm package fullpage.js
CVE-2023-0842 Vulnerability in maven package org.webjars.npm:xml2js
CVE-2023-37912 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-macro-footnotes
CVE-2020-6422 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-28281 Vulnerability in npm package set-object-value