CVE-2024-1198
openBI Phar User.php addxinzhi deserialization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696.
Una vulnerabilidad fue encontrada en openBI hasta 6.0.3 y clasificada como crítica. La función addxinzhi del archivo application/controllers/User.php del componente Phar Handler es afectada por esta vulnerabilidad. La manipulación del argumento outimgurl conduce a la deserialización. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-252696.
Es wurde eine Schwachstelle in openBI bis 6.0.3 gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist die Funktion addxinzhi der Datei application/controllers/User.php der Komponente Phar Handler. Durch Manipulation des Arguments outimgurl mit unbekannten Daten kann eine deserialization-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-02 CVE Reserved
- 2024-02-02 CVE Published
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- 2025-02-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.252696 | Technical Description |
URL | Date | SRC |
---|---|---|
https://note.zhaoj.in/share/qFXZZfp1NLa3 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openbi Search vendor "Openbi" | Openbi Search vendor "Openbi" for product "Openbi" | >= 6.0.0 <= 6.0.3 Search vendor "Openbi" for product "Openbi" and version " >= 6.0.0 <= 6.0.3" | - |
Affected
|