Description
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
Remediation
References
http://ureport.com
https://github.com/Venus-WQLab/bug_report/blob/main/ureport/ureport-cve-2023-24188.md
https://github.com/youseries/ureport
Related Vulnerabilities
CVE-2020-28270 Vulnerability in npm package object-hierarchy-access
CVE-2023-22893 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2023-29511 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2023-30518 Vulnerability in maven package io.jenkins.plugins:thycotic-secret-server
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-webflux