CVE Vulnerabilities

CVE-2023-50090

Published: Jan 03, 2024 | Modified: Jan 09, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.

Affected Software

Name Vendor Start Version End Version
Ureport2 Ureport2_project * 2.2.9 (including)

References