Record summary

CVE-2023-7305 has a selected CVSS score of 9.2 (critical).

Description

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 14, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListV8 to < July 2023 updateaffected
V9 to < July 2023 updateaffected
V10 to < July 2023 updateaffected
VulnCheckVersion data not supplied

References

5