CVE-2020-21125 is an arbitrary file creation vulnerability in UReport 2.2.9 that allows attackers to execute arbitrary code. This critical vulnerability has a CVSS score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability compromise possible via a network-based attack requiring no user interaction. While the EPSS score is low, suggesting a lower likelihood of exploitation compared to many other CVEs, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.9CPE matchmatch criteria | cpe:2.3:a:ureport_project:ureport:2.2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.