CVE-2020-21124: Ureport Project Ureport
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
Affected products
- Ureport Project Ureport: version 2.2.9 only
Published 2021-09-15. Last modified 2026-06-17.