CyberRota Analysis
AI-GeneratedA directory traversal vulnerability in reportico-web versions up to 8.1.0 allows remote attackers to access or execute arbitrary PHP files on the web server by manipulating the target_format parameter alongside the execute_mode=EXECUTE parameter in the run.php endpoint. This could lead to unauthorized access to sensitive files or execution of malicious scripts, posing a significant risk to the integrity and confidentiality of the server. Organizations using affected versions should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint.