Authenticated SQL Injection Vulnerability in Cloudlog by Magicbug
CVE-2025-64084
What is CVE-2025-64084?
An authenticated SQL injection vulnerability has been identified in Cloudlog 2.7.5 and earlier versions. The vulnerability arises from the improper sanitization of the Gridsquare POST parameter within the vucc_details_ajax function in the application/controllers/Awards.php file. This oversight permits remote, authenticated attackers to inject malicious SQL commands, which may be executed by concatenating them into an unprotected SQL query within the vucc_qso_details function. This could lead to sensitive data exposure or complete database compromise if exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
