PT-2025-38227 · Unknown · Swetrix Web Analytics Api
Depthfirstdisclosures
·
Published
2025-09-17
·
Updated
2025-11-09
·
CVE-2025-59304
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Swetrix Web Analytics API versions prior to 7d8b972
Description
A directory traversal issue exists in Swetrix Web Analytics API 3.1.1 before commit 7d8b972. This allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request.
Recommendations
Update Swetrix Web Analytics API to version 7d8b972 or later.
Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swetrix Web Analytics Api