CVE-2024-1032
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 30, 2024
Updated: May 17, 2024
CWE ID 502
Summary
CVE-2024-1032: A critical deserialization vulnerability has been identified in openBI versions up to 1.0.8. The issue lies within the Test Connection Handler's function testConnection located in /application/index/controller/Databasesource.php. Exploitation of this vulnerability results in deserialization and can be executed remotely. The exploit for this weakness has been made public, increasing the risk of potential attacks. (VDB-252307)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share