PT-2024-33057 · Wavelog · Wavelog

Published

2024-10-14

·

Updated

2024-10-19

·

CVE-2024-48251

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavelog version 1.8.5
Description The issue is an SQL injection vulnerability in the Activated gridmap model.php file. This vulnerability can be exploited through the band, sat, propagation, or mode variables.
Recommendations For Wavelog version 1.8.5, as a temporary workaround, consider restricting access to the Activated gridmap model.php file until a patch is available. Avoid using the variables band, sat, propagation, or mode in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-48251

Affected Products

Wavelog