Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cloudlog 安全漏洞
Vulnerability Description
Cloudlog是Peter Goodhall个人开发者的一个自托管的 PHP 应用程序。允许在任何地方记录业余无线电联系人。 Cloudlog 2.7.5及之前版本存在安全漏洞,该漏洞源于Awards.php中vucc_details_ajax函数未正确清理Gridsquare参数,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A