A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is the function agent of the file /application/index/controller/Datament.php. The manipulation of the argument api leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252308.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://vuldb.com/?id.252308 | vdb entry third party advisory technical description |
https://vuldb.com/?ctiid.252308 | signature permissions required third party advisory |
https://note.zhaoj.in/share/nD654ot6zRQZ | broken link exploit |