Key Information Vulnerability Details CVE ID: CVE-2025-59397 Vulnerability Type: SQL Injection Affected Versions: Open Web Analytics 1.8.0 and earlier Discovery Date: June 2, 2025 Public Disclosure Date: October 6, 2025 Technical Details Affected File: (Line numbers: 540 and 601) Critical Code Snippet: Issue Description: When processing constraints containing the or operators, user input is directly inserted into SQL statements, leading to SQL injection. Impact Authorized users can execute arbitrary SQL queries Potential data leakage Risk of privilege escalation Mitigation Recommendation Upgrade to Open Web Analytics 1.8.1 to resolve this vulnerability.