PT-2024-31877 · Cloudlog · Cloudlog

Published

2024-10-01

·

Updated

2024-10-07

·

CVE-2024-45999

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloudlog version 2.6.15
Description A SQL Injection issue was discovered, specifically within the get station info() function located in the file /application/models/Oqrs model.php. The issue is exploitable via the station id parameter. This allows for remote code execution.
Recommendations For Cloudlog version 2.6.15, patch immediately and review logs for signs of compromise. As a temporary workaround, consider restricting access to the get station info() function until a patch is available. Avoid using the station id parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-45999

Affected Products

Cloudlog