CVE-2023-7305 - CVE House
Back to Database
Status published Critical CVE-2023-7305

SmartBI RMIServlet Unrestricted File Upload RCE

Vulnerability Description

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-7305

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Guangzhou Smart Software Co., Ltd.

View all reports →

Affected Software

SmartBI
Vulnerable Versions:
V8, V9, V10

Timeline

Official Publish: October 15th, 2025
Last Modified: November 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)