PT-2026-77234 · Undefined · Undefined
CVE-2026-52610
·
Published
2026-08-18
·
Updated
2026-08-31
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
reportico-web versions prior to 8.1.1
Description
An arbitrary file write and directory traversal issue exists where remote attackers can create or overwrite files on the filesystem based on the web user permissions. This occurs at the 'run.php' endpoint when the
saveTemplate parameter is used in conjunction with the execute mode=PREPARE parameter.Recommendations
Update reportico-web to a version newer than 8.1.0.
Avoid using the
saveTemplate parameter at the 'run.php' endpoint until the software is updated.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined