PT-2022-16769 · Unknown · Open Web Analytics

Scryh

·

Published

2022-03-18

·

Updated

2025-11-10

·

CVE-2022-24637

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Web Analytics versions prior to 1.7.4
Description The issue allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php' (instead of the intended "<?php" sequence) aren't handled by the PHP interpreter.
Recommendations For versions prior to 1.7.4, update to version 1.7.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information and cache hashes until a patch is applied.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-24637
GHSA-PR9Q-V585-QV2W

Affected Products

Open Web Analytics