#VU76160 Improper access control in Open Web Analytics - CVE-2022-24637

 

#VU76160 Improper access control in Open Web Analytics - CVE-2022-24637

Published: May 15, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU76160
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2022-24637
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Open Web Analytics
Software vendor:
Open Web Analytics

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.


Remediation

Install updates from vendor's website.

External links