magicbug Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with magicbug products.
Products
- cloudlog3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-48259HIGH | Cloudlog - SQL InjectionCloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | CVSS7.3v3.1 | EPSS0.907% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-48253CRITICAL | Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. CWE-89Oct 14, 2024 | CVSS9.8v3.1 | EPSS0.441% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-48255CRITICAL | Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. CWE-89Oct 14, 2024 | CVSS9.8v3.1 | EPSS0.441% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |