VulnerabilityDeferred
CVE-2025-59397
Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
MEDIUM 5.0EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
- CVSS 3.1
- 5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Source
- cve@mitre.org
References
- https://github.com/Open-Web-Analytics/Open-Web-Analytics/commit/1e5531522acb8f145627c9feb0175cf8a66561ba
- https://github.com/Open-Web-Analytics/Open-Web-Analytics/compare/1.8.0...1.8.1
- https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.8.1
- https://seclists.org/fulldisclosure/2025/Oct/5
- https://www.openwebanalytics.com
- https://www.seralys.com/research/CVE-2025-59397.txt
- http://seclists.org/fulldisclosure/2025/Oct/5
- https://seclists.org/fulldisclosure/2025/Oct/5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.