Authenticated SQL Injection Vulnerability in Cloudlog by Magicbug
CVE-2025-64084

5.4MEDIUM

Key Information:

Vendor

Magicbug

Status
Vendor
CVE Published:
14 November 2025

What is CVE-2025-64084?

An authenticated SQL injection vulnerability has been identified in Cloudlog 2.7.5 and earlier versions. The vulnerability arises from the improper sanitization of the Gridsquare POST parameter within the vucc_details_ajax function in the application/controllers/Awards.php file. This oversight permits remote, authenticated attackers to inject malicious SQL commands, which may be executed by concatenating them into an unprotected SQL query within the vucc_qso_details function. This could lead to sensitive data exposure or complete database compromise if exploited.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64084 : Authenticated SQL Injection Vulnerability in Cloudlog by Magicbug