{"id":"CVE-2025-63261","details":"AWStats 8.0 is vulnerable to Command Injection via the open function","modified":"2026-07-15T01:48:55.347108348Z","published":"2026-03-20T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/63xxx/CVE-2025-63261.json"},"references":[{"type":"WEB","url":"https://github.com/eldy/AWStats/blob/develop/wwwroot/cgi-bin/awstats.pl"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/03/msg00013.html"},{"type":"WEB","url":"https://pentest-tools.com/PTT-2025-021-Code-Execution-in-AWStats.pdf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/63xxx/CVE-2025-63261.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-63261"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eldy/awstats","events":[{"introduced":"490b723082690764889ac710efa4a0772b8259d0"},{"last_affected":"490b723082690764889ac710efa4a0772b8259d0"}],"database_specific":{"cpe":"cpe:2.3:a:awstats:awstats:7.9:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.9"},{"last_affected":"7.9"}],"source":"CPE_STRING"}}],"versions":["7.9","AWSTATS_7_9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63261.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}