Unknown · Lakernote Easyadmin · CVE-2024-2827
**Name of the Vulnerable Software and Affected Versions**
lakernote EasyAdmin up to 20240315
**Description**
A critical issue has been found in lakernote EasyAdmin, affecting some unknown processing of the file "/ureport/designer/saveReportFile". The manipulation leads to server-side request forgery. The attack may be initiated remotely.
**Recommendations**
For lakernote EasyAdmin up to 20240315, consider disabling access to the "/ureport/designer/saveReportFile" file until a patch is available. Restrict access to this file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.