CVE-2023-24187: Ureport Project Ureport
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
Affected products
- Ureport Project Ureport: version 2.2.9 only
Published 2023-02-14. Last modified 2026-07-09.