Open.Web.Analytics.CVE-2022-24637.Remote.Code.Execution

description-logoDescription

This indicates an attack attempt to exploit an Remote Code Injection Vulnerability in Open Web Analytics.
The vulnerability is due to an error when handling an upload request. A remote attacker could exploit the vulnerability by sending crafted requests to the target server. Successful exploitation can result in arbitrary code execution under the security context of SYSTEM.

affected-products-logoAffected Products

Open Web Analytics version 1.7.3 and prior

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Please update to the latest version from the vendor.
https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2023-04-12 23.534
Modified
Default_action:pass:drop
2023-03-30 23.524
New