Idearespa's vulnerability footprint is concentrated in its RefTree product, a file-management or document-handling application where the observed weaknesses center on path-traversal and unrestricted-file-upload flaws that are typical of systems handling user-supplied file operations. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idearespa over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27249HIGH An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted asp | Apr 3, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-27248MEDIUM A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an abs | Apr 3, 2022 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idearespa.
Media articles that mention a CVE ID that affects a product developed by Idearespa — matched by CVE ID, not by vendor name.