CVE-2025-64084

An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:magicbug:cloudlog:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-14 21:15

Updated : 2025-11-19 18:50


NVD link : CVE-2025-64084

Mitre link : CVE-2025-64084

CVE.ORG link : CVE-2025-64084


JSON object : View

Products Affected

magicbug

  • cloudlog
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')