CVE-2023-24187: Ureport Project Ureport

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

Affected products

Published 2023-02-14. Last modified 2026-07-09.