See how reportico compares to other vendors in security performance
An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via executemode parameter of the URL.
Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter.
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the targetformat parameter in conjunction with the executemode=EXECUTE parameter of the run.php endpoint.
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "executemode=PREPARE" parameter in the "run.php" endpoint.