PT-2026-98852 · Unknown · Open Web Analytics
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Open-Web-Analytics versions prior to 1.8.2
Description
A flaw in the Remote Event Queue Endpoint component allows remote attackers to trigger deserialization by manipulating the
Event::loadFromArray() function within the queue.php file. Deserialization is a process where data stored in a format like JSON or XML is converted back into an object that the application can use, which can be exploited to execute unauthorized code if the input is not properly validated.Recommendations
Update to version 1.8.2.
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Web Analytics