CVE-2024-45999
CVE-2024-45999: A critical SQL Injection vulnerability exists in Cloudlog 2.6.15, allowing attackers to potentially execute arbitrary SQL commands. The flaw resides in the get_station_info() function within /application/models/Oqrs_model.php, and is triggered via the station_id parameter. Given the SOCRadar Vulnerability Risk Score (SVRS) of 84, this vulnerability requires immediate attention. This high score indicates that threat actors are actively exploiting this vulnerability. Successful exploitation could lead to unauthorized data access, modification, or deletion. Due to the ease of exploitation and potential for significant damage, patching or mitigating this vulnerability is critical to protect your systems from potential attacks. This vulnerability allows attackers to manipulate database queries, potentially compromising sensitive information and system integrity.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.