PT-2026-95089 · Wavelog · Wavelog
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Wavelog versions 1.8 through 2.4.1
Description
Wavelog exposes the endpoints '/install/ajax.php' and '/install/includes/interface assets/triggers.php' after installation without requiring an installation lock or permission check. Unsanitized input reaches the functions
write config() and write configfile() in install/includes/core/core class.php, enabling a remote unauthenticated attacker to read or write log files and insert controlled content into PHP configuration files, which can lead to remote code execution on the server.Recommendations
Update to version 2.4.2.
Exploit
Fix
Code Injection
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wavelog