Medium severity5.0NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026
CVE-2025-59397
CVE-2025-59397
Description
Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-web-analytics/open-web-analyticsPackagist | < 1.8.1 | 1.8.1 |
Affected products
1Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-6w8r-xgqq-qg6gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-59397ghsaADVISORY
- github.com/Open-Web-Analytics/Open-Web-Analytics/commit/1e5531522acb8f145627c9feb0175cf8a66561banvdWEB
- github.com/Open-Web-Analytics/Open-Web-Analytics/compare/1.8.0...1.8.1nvdWEB
- github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.8.1nvdWEB
- seclists.org/fulldisclosure/2025/Oct/5nvdWEB
- www.openwebanalytics.comnvdWEB
- www.seralys.com/research/CVE-2025-59397.txtnvdWEB
- seclists.org/fulldisclosure/2025/Oct/5nvd
News mentions
0No linked articles in our index yet.