PT-2024-31877 · Cloudlog · Cloudlog

CVE-2024-45999

·

Published

2024-10-01

·

Updated

2024-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloudlog version 2.6.15
Description A SQL Injection issue was discovered, specifically within the get station info() function located in the file /application/models/Oqrs model.php. The issue is exploitable via the station id parameter. This allows for remote code execution.
Recommendations For Cloudlog version 2.6.15, patch immediately and review logs for signs of compromise. As a temporary workaround, consider restricting access to the get station info() function until a patch is available. Avoid using the station id parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45999

Affected Products

Cloudlog