CVE-2023-24188
Critical · CVSS 9.1ureport2-core (UReport2) — Path Traversal / Directory Traversal leading to Arbitrary File Deletion (CWE-22)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-22, CWE-22
Description
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
Search profile — drives PoC discovery
Symbols ureport2-coredeletion functioncom.bstek.ureportureport2UReport2file deletepath traversaldeleteFilereportName../
Keywords CVE-2023-24188ureport2ureport v2.2.9directory traversalarbitrary file deletionureport2-core path traversalureport delete exploitureport CVE-2023-24188 PoCVenus-WQLab ureportcom.bstek.ureport traversal
Versions: v2.2.9
Affected packages
| Maven | com.bstek.ureport:ureport2-core | 0 → ∞ |
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z