Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr9q-v585-qv2w

Опубликовано: 19 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper Privilege Management in Open Web Analytics

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

Пакеты

Наименование

open-web-analytics/open-web-analytics

composer
Затронутые версииВерсия исправления

< 1.7.4

1.7.4

EPSS

Процентиль: 100%
0.93978
Критический

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

EPSS

Процентиль: 100%
0.93978
Критический

9.8 Critical

CVSS3

Дефекты

CWE-269