PT-2025-47009 · Cloudlog · Cloudlog

Published

2025-11-14

·

Updated

2025-11-19

·

CVE-2025-64084

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cloudlog versions 2.7.5 and earlier
Description An authenticated SQL injection issue exists. The vucc details ajax function within the application/controllers/Awards.php file does not properly sanitize the Gridsquare POST parameter provided by the user. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload. The payload is then directly concatenated into a raw SQL query within the vucc qso details function.
Recommendations Versions prior to 2.7.5 should be updated.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-64084
GHSA-4R9R-3R3Q-JG44

Affected Products

Cloudlog