Improper access control in Open Web Analytics - CVE-2022-24637

 

Improper access control in Open Web Analytics - CVE-2022-24637

Published: May 15, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU76160
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24637
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.


Affected software

Open Web Analytics

How to mitigate CVE-2022-24637

Install updates from vendor's website.

Open Web Analytics - update to 1.7.4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins