Vulnerability Details CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.935
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2022-24637
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.2
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.3
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.4
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.5
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.6
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.7
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.0.8
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.1.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.1.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.2.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.2.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.2.2
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.2.3
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.2.4
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.3.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.3.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.4.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.4.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.0
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.2
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.3
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.4
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.5
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.6
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.5.7
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.6.1
-
cpe:2.3:a:openwebanalytics:open_web_analytics:1.6.2