CVE-2024-1117
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 31, 2024
Updated: May 17, 2024
CWE ID 94
Summary
CVE-2024-1117 is a critical vulnerability affecting openBI versions up to 1.0.8. The issue lies in the function index of the /application/index/controller/Screen.php file. An attacker can exploit this vulnerability by manipulating the fileurl argument to inject code. The exploit can be launched remotely, making it a significant threat. The vulnerability has been disclosed to the public, increasing the risk of widespread exploitation, with the associated identifier being VDB-252475.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.