VYPR
High severity7.3NVD Advisory· Published Jan 30, 2024· Updated Jun 17, 2026

CVE-2024-1034

CVE-2024-1034

Description

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252309 was assigned to this vulnerability.

Affected products

3
  • cpe:2.3:a:openbi_project:openbi:*:*:*:*:*:*:*:*
    Range: <=1.0.8
  • openBI/openBIcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.0.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.