PoC Index

CVE-2022-24637

CRITICAL 9.8EPSS 99.1%

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
99.06% chance of exploitation in the next 30 days, 100th percentile
Nuclei
critical · CWE-269
Published
2022-03-18
Updated
2024-08-03

Proof-of-concept exploits (9)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related