PT-2025-38227 · Unknown · Swetrix Web Analytics Api

Depthfirstdisclosures

·

Published

2025-09-17

·

Updated

2025-11-09

·

CVE-2025-59304

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Swetrix Web Analytics API versions prior to 7d8b972
Description A directory traversal issue exists in Swetrix Web Analytics API 3.1.1 before commit 7d8b972. This allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request.
Recommendations Update Swetrix Web Analytics API to version 7d8b972 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-59304

Affected Products

Swetrix Web Analytics Api