PT-2025-38227 · Unknown · Swetrix Web Analytics Api

·

CVE-2025-59304

·

Published

2025-09-17

·

Updated

2025-11-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Swetrix Web Analytics API versions prior to 7d8b972
Description A directory traversal issue exists in Swetrix Web Analytics API 3.1.1 before commit 7d8b972. This allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request.
Recommendations Update Swetrix Web Analytics API to version 7d8b972 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59304

Affected Products

Swetrix Web Analytics Api