Time-based Blind SQL Injection in Cloudlog by Magicbug
CVE-2024-44065
9.8CRITICAL
What is CVE-2024-44065?
A time-based blind SQL injection vulnerability exists in Cloudlog v2.6.15, specifically within the /index.php/logbookadvanced/search endpoint when processing input through the qsoresults parameter. An attacker could exploit this weakness to execute arbitrary SQL queries against the database, leading to unauthorized data access or manipulation.
