Impact
A directory traversal flaw (CWE-22) in reportico-web versions up to 8.1.0 lets remote attackers specify a file name via the target_format parameter together with execute_mode=EXECUTE on the run.php endpoint, causing the web server to read or run arbitrary PHP files, resulting in remote code execution and potentially full compromise of the server.
Affected Systems
The vulnerability affects all deployments of Reportico-Web 8.1.0 and earlier. No vendor or product version list beyond this is provided. Systems running these versions should consider the risk.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium‑to‑high severity, and the EPSS score is < 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can craft HTTP requests to the run.php endpoint with the target_format and execute_mode=EXECUTE parameters, bypassing normal validations. The ability to execute arbitrary PHP code gives full access to the underlying server.
OpenCVE Enrichment