CVE-2022-24637
CRITICAL 9.8EPSS 99.1%
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 99.06% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-269
- Published
- 2022-03-18
- Updated
- 2024-08-03
Proof-of-concept exploits (9)
- http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Executio…
- 0xM4hm0ud/CVE-2022-246373★ · 2023-03-26
- 0xRyuk/CVE-2022-246371★ · 2023-08-22
- Lay0us/CVE-2022-246375★ · 2022-08-30
- Lay0us1/CVE-2022-246375★ · 2022-08-30
- Pflegusch/CVE-2022-246374★ · 2023-04-08
- hupe1980/CVE-2022-246375★ · 2022-10-12
- icebreack/CVE-2022-246374★ · 2022-11-15
- 726232111/CVE-2022-24638