THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-7305 — SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute

[NVD] CVE-2023-7305 — SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute

lownvdPublished 2025-10-15

CVE-2023-7305 CVSS: None Published: 2025-10-15T02:15:32.010

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-7305