CVE-2018-15537: Ocsinventory-NG Ocsinventory NG

High severity, CVSS 8.8. EPSS: 5% chance of exploitation in the next 30 days.

Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.

Affected products

Published 2018-11-29. Last modified 2026-06-17.