Impact
A flaw in the checkCapabilityAndAuthenticateUser function of Core/Controller.php allows an attacker to manipulate input and bypass the authentication checks. This results in improper authentication, which can grant unauthorized users access to application functionality or data. The weakness is identified as CWE‑287, an authentication bypass issue.
Affected Systems
The vulnerability exists in Open‑Web‑Analytics versions up to and including 1.9.1. The vendor is Open‑Web‑Analytics, and the affected component is the Controller module. Version 1.10.0 patches the issue, as indicated by the referenced commit.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is uncertain. The remote attacker initiates the attack by manipulating requests to the vulnerable function, potentially gaining unauthorized access to the system.
OpenCVE Enrichment