← Back to browse · API

CVE-2022-25767

Severity
CRITICAL
CVSS
9.8
EPSS
0.02993
Risk score
40.25
CISA KEV
No
PoC
No
Published
2022-05-01
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-5476, GHSA-W39X-CHVM-PJ3C
Products
n/a:com.bstek.ureport:ureport2-console 0 <unspecified
Sources
euvd EUVD-2022-5476

Description

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

References