PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-48259

7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
cloudlog
Updated Sep 18, 2026View on NVD →
S4E scanner
highWeb Vulnerabilities~10 seconds

Cloudlog - SQL Injection

Cloudlog 2.6.15 contains a SQL injection caused by unsanitized input in oqrs.php request_form, letting attackers execute arbitrary SQL commands via station_id or callsign, exploit requires sending crafted request. References: https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in-9a3 https://github.com/magicbug/Cloudlog https://nvd.nist.gov/vuln/detail/CVE-2024-48259 Remediation: Update to the latest version of Cloudlog where this issue is fixed, or sanitize inputs properly.

Used 3.1k times · domain, subdomain, ipv4

CVE history: cloudlog

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →