Description
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
Remediation
References
http://ureport.com
https://github.com/Venus-WQLab/bug_report/blob/main/ureport/ureport-cve-2023-24188.md
https://github.com/youseries/ureport
Related Vulnerabilities
CVE-2022-24429 Vulnerability in npm package convert-svg-core
CVE-2019-10790 Vulnerability in npm package taffy
CVE-2021-23797 Vulnerability in npm package http-server-node
CVE-2017-1000228 Vulnerability in npm package ejs
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.velocity