Improper access control in Open Web Analytics - CVE-2022-24637
Published: May 15, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.
Affected software
How to mitigate CVE-2022-24637
Links to Public Exploits and PoC-codes
- Exploit #10683 - Open Web Analytics 1.7.3 - Remote Code Execution (October 25, 2024)
- Exploit #10476 - CVE-2022-24637 (Unauthenticated RCE in Open Web Analytics version <1.7.4) (August 30, 2024)
- Exploit #9388 - CVE-2022-24637 (Unauthicated RCE for open-web-analytics(1.7.3)) (October 22, 2023)
- Exploit #9387 - CVE-2022-24637 (Open Web Analytics 1.7.3 - Remote Code Execution) (October 22, 2023)
- Exploit #9386 - CVE-2022-24637 (Open Web Analytics (OWA) - Unauthenticated Remote Code Execution) (October 22, 2023)
- Exploit #9326 - CVE-2022-24637 (Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3) (September 18, 2023)
- Exploit #9254 - CVE-2022-24637 (Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2) (August 22, 2023)
- Exploit #9195 - CVE-2022-24637 (FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)) (July 19, 2023)
- Exploit #9075 - Open Web Analytics 1.7.3 - Remote Code Execution (RCE) (May 15, 2023)