Authenticated SQL Injection Vulnerability in Cloudlog by Magicbug
CVE-2025-64084
5.4MEDIUM
What is CVE-2025-64084?
An authenticated SQL injection vulnerability has been identified in Cloudlog 2.7.5 and earlier versions. The vulnerability arises from the improper sanitization of the Gridsquare POST parameter within the vucc_details_ajax function in the application/controllers/Awards.php file. This oversight permits remote, authenticated attackers to inject malicious SQL commands, which may be executed by concatenating them into an unprotected SQL query within the vucc_qso_details function. This could lead to sensitive data exposure or complete database compromise if exploited.
