CVE-2023-24188 is a critical directory traversal vulnerability affecting ureport v2.2.9, allowing unauthenticated attackers to delete arbitrary files. With a CVSS score of 9.1, it poses a high risk due to its network-based attack vector and low complexity, leading to potential complete loss of integrity and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, the vulnerability has garnered significant community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.9CPE matchmatch criteria | cpe:2.3:a:ureport_project:ureport:2.2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.