CVE-2025-59397
MEDIUMOpen Web Analytics < 1.8.1 - SQL Injection via owa_db.php v Parameter
Title source: llmDescription
Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
References (7)
Core 7
Core References
Various Sources
https://www.openwebanalytics.com
Various Sources
https://www.seralys.com/research/CVE-2025-59397.txt
Mailing List
https://seclists.org/fulldisclosure/2025/Oct/5
Mailing List
http://seclists.org/fulldisclosure/2025/Oct/5
Scores
CVSS v3
5.0
EPSS
0.0039
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (2)
open-web-analytics/open-web-analytics
0 - 1.8.1Packagist
openwebanalytics/Open Web Analytics
< 1.8.1
Published
Sep 15, 2025
Tracked Since
Feb 18, 2026