CVE-2022-24637 is an information disclosure vulnerability in Open Web Analytics (OWA) prior to version 1.7.4. The vulnerability arises from improper use of single quotes in PHP when generating cache files, resulting in files starting with '<?php instead of '<?php'. As a result, these files are not interpreted as PHP and are served as plain text, exposing sensitive user information such as the admin temp_passkey. This temp_passkey can be used to reset the admin password, enabling privilege escalation. When chained with a separate vulnerability that allows arbitrary PHP file writes by an authenticated admin, this can lead to unauthenticated remote code execution (RCE) on the webserver.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains a defensive README and one functional Python 3 exploit script, owa_exploit.py. Despite the README claiming that no exploit code is included, the script implements an exploitation chain for CVE-2022-24637 affecting Open Web Analytics releases before 1.7.4. It normalizes an operator-supplied target URL, enumerates likely owa-data/caches/<key>/owa_user/ cache locations using MD5-derived candidate user IDs, extracts base64-encoded serialized cache data, and searches it for a 32-character temp_passkey. It then submits that key to OWA's password-reset endpoint, attempts login with a generated 12-character password, retrieves an administrative CSRF nonce, and invokes an error-log exploitation stage intended to yield a PHP-based callback shell to the supplied listener. The script also contains fallback checks named exploit_file_upload and exploit_sql_injection, whose success messages say manual exploitation is needed. The full bodies of several later functions are truncated in the supplied content, so exact request paths and payload bytes for nonce retrieval, log exploitation, upload probing, and SQL-injection probing cannot be verified from this archive extract. No established exploit framework is used.
This repository contains a single Metasploit module (Ruby file) that exploits a remote code execution (RCE) vulnerability in Open Web Analytics (OWA) versions prior to 1.7.4 (CVE-2022-24637). The exploit works by leveraging a flaw in the way OWA handles cache files, allowing an unauthenticated attacker to extract sensitive information and reset the password of a user (default: admin). The module then logs in as the compromised user, updates the OWA configuration to write a PHP payload (default: meterpreter reverse shell) to the server's cache directory, and triggers its execution, resulting in remote code execution as the web server user. The exploit is weaponized, supporting customizable payloads via the Metasploit framework. The main attack vector is network-based, targeting the OWA web interface via HTTP requests. The module interacts with several OWA endpoints, including login, password reset, configuration update, and cache file access. The exploit leaves artifacts on disk and in logs, and changes account passwords and configuration files on the target. The repository is structured as a single Ruby file compatible with Metasploit, and is intended for use within the framework.
This repository contains a working exploit for CVE-2022-24637, a remote code execution vulnerability in Open Web Analytics (OWA) version 1.7.3 and below. The exploit consists of a Python script (exploit.py) and a PHP reverse shell payload (php-reverse-shell.php, based on Pentestmonkey's well-known script). The exploit works by abusing OWA's cache and configuration mechanisms to reset a user's password, log in as that user, and then write the PHP reverse shell to a writable directory on the server. The attacker must configure their own IP and port in the PHP payload, then run the Python script against the target OWA instance. If successful, the attacker can trigger the reverse shell by accessing its URL, resulting in a shell connection back to the attacker's machine. The repository is structured with a README for usage instructions, the main exploit script, and the PHP payload. The attack vector is network-based, targeting web endpoints exposed by OWA. The exploit is operational, requiring some manual configuration but providing a working reverse shell if the target is vulnerable.
This repository contains a Python exploit script (CVE-2022-24637.py) and a README for CVE-2022-24637, an unauthenticated remote code execution vulnerability in Open Web Analytics (OWA) versions prior to 1.7.4. The exploit automates the attack by first attempting to retrieve a temporary key from a user cache file, then resetting the admin password, and finally uploading a PHP reverse shell to the OWA logs directory by abusing the application's settings. The attacker must provide the target URL, a new admin password, and their own IP and port for the reverse shell. The exploit is operational and provides a working reverse shell if successful. The main attack vector is network-based, targeting the OWA web interface. Key fingerprintable endpoints include the OWA login page, cache files, and the logs directory where the shell is written. The repository is straightforward, with one main Python exploit file and a README describing usage and context.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.