← back
CVE-2022-24637

CVE-2022-24637

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 99%
from disclosure to weapon165 days
Published on NVDMar 18
1st PoC+165d
metasploitMar 18
exploitation probability
99%top 1% of all CVEs
observed exploitation
nono source reports it
9 public exploit(s)
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.