CVSS 3.1 Score 9.8 of 10 (high)


Published Jan 31, 2024
Updated: Mar 21, 2024


CVE-2024-1115 is a critical vulnerability found in openBI up to version 1.0.8. The vulnerability affects the function dlfile of the file /application/websocket/controller/Setting.php, allowing for remote initiation of an OS command injection through manipulation of the argument phpPath. The exploit has been publicly disclosed and may be utilized by attackers. This vulnerability poses a high danger to organizations as it has a base severity rating of CRITICAL, with high impacts on confidentiality, integrity, and availability of affected systems. It has a CVSS score of 9.8 out of 10 and affects various products including usu_3g, usu_3h, usu_3i, usu_3j, usu_3k, usu_3l, usu_3m, usu_3n, and usu_3o. It is recommended to apply remediation measures promptly to mitigate the risk posed by this vulnerability.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-1115 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options