CVE-2022-24637
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
9.8
CVSS
99.1%
EPSS (exploit prob.)
100th
EPSS percentile
2022-03-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openwebanalytics | open_web_analytics | < 1.7.4 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html
- https://devel0pment.de/?p=2494
- https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4
- http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html
- https://devel0pment.de/?p=2494
- https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-24637