CVE-2014-1456
Openwebanalytics Open Web Analytics < 1.5.5 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.
References (5)
Scores
EPSS
0.0032
EPSS Percentile
54.8%
Details
CWE
CWE-79
Status
published
Products (48)
openwebanalytics/open_web_analytics
< 1.5.5
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
openwebanalytics/open_web_analytics
... and 38 more
Published
Mar 01, 2014
Tracked Since
Feb 18, 2026