CVE-2024-1115
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-1115 is a critical vulnerability affecting openBI up to version 1.0.8. This issue lies in the Setting.php file, specifically the dlfile function located at /application/websocket/controller/Setting.php. The vulnerability stems from the manipulation of the phpPath argument, which can lead to os command injection. An attacker can initiate this exploit remotely, making it a significant risk. The vulnerability has been disclosed to the public, increasing the threat of exploitation. The Vulnerability Database has assigned the identifier VDB-252473 to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.