CVE-2014-1456

Openwebanalytics Open Web Analytics < 1.5.5 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.

Scores

EPSS 0.0032
EPSS Percentile 54.8%

Details

CWE
CWE-79
Status published
Products (48)
openwebanalytics/open_web_analytics < 1.5.5
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
... and 38 more
Published Mar 01, 2014
Tracked Since Feb 18, 2026