Open Web Analytics 1.7.3 Remote Code Execution
Posted by deepcore on March 18, 2023 – 10:24 am
Open Web Analytics (OWA) versions prior to 1.7.4 allow an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.
Post a reply
You must be logged in to post a comment.