CVE-2022-24637

CRITICAL NUCLEI LAB

Open Web Analytics <1.7.4 - Info Disclosure

Title source: llm

Description

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

Exploits (9)

exploitdb WORKING POC
by Jacob Ebben · pythonwebappsphp
https://www.exploit-db.com/exploits/51026
nomisec WORKING POC 5 stars
by hupe1980 · poc
https://github.com/hupe1980/CVE-2022-24637
nomisec WORKING POC 5 stars
by Lay0us · poc
https://github.com/Lay0us/CVE-2022-24637
nomisec WORKING POC 4 stars
by Pflegusch · poc
https://github.com/Pflegusch/CVE-2022-24637
nomisec WORKING POC 4 stars
by icebreack · poc
https://github.com/icebreack/CVE-2022-24637
nomisec WORKING POC 3 stars
by 0xM4hm0ud · poc
https://github.com/0xM4hm0ud/CVE-2022-24637
nomisec WORKING POC 1 stars
by 0xRyuk · poc
https://github.com/0xRyuk/CVE-2022-24637
nomisec WORKING POC
by JacobEbben · poc
https://github.com/JacobEbben/CVE-2022-24637
metasploit WORKING POC EXCELLENT
by Jacob Ebben, Dennis Pfleger · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/open_web_analytics_rce.rb

Nuclei Templates (1)

Open Web Analytics 1.7.3 - Remote Code Execution
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan: cpe:"cpe:2.3:a:openwebanalytics:open_web_analytics"

Scores

CVSS v3 9.8
EPSS 0.9385
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull ghcr.io/pflegusch/owa-rce:1.7.3
+5 more repos

Details

CWE
CWE-269
Status published
Products (2)
open-web-analytics/open-web-analytics 0 - 1.7.4Packagist
openwebanalytics/open_web_analytics < 1.7.4
Published Mar 18, 2022
Tracked Since Feb 18, 2026