Cloudlog 2.6.15 contains a SQL injection caused by unsanitized input in oqrs.php request_form, letting attackers execute arbitrary SQL commands via station_id or callsign, exploit requires sending crafted request.
id: CVE-2024-48259
info:
name: Cloudlog - SQL Injection
author: s4e-io
severity: high
descr
...