CVE-2025-59397: SQL Injection
Published Sep 15, 2025
·Updated
Open Web Analytics (OWA) before 1.8.1 allows owadb.php v[value] SQL injection.
Affected Software
1 affected component
Open Web Analytics Open Web Analytics<1.8.1
Event History
Sep 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-59397?
CVE-2025-59397 has a medium severity rating due to its potential for SQL injection vulnerabilities in Open Web Analytics before version 1.8.1.
2
How do I fix CVE-2025-59397?
To fix CVE-2025-59397, upgrade Open Web Analytics to version 1.8.1 or later where the vulnerability has been addressed.
3
What kind of vulnerability is CVE-2025-59397?
CVE-2025-59397 is an SQL injection vulnerability found in the owa_db.php file of Open Web Analytics.
4
Which versions are affected by CVE-2025-59397?
CVE-2025-59397 affects all versions of Open Web Analytics before version 1.8.1.
5
Can CVE-2025-59397 be exploited remotely?
Yes, CVE-2025-59397 can be exploited remotely if an attacker can send malicious input to the owa_db.php script.