CVE-2025-64084
MEDIUMCloudlog < 2.7.6 - Authenticated SQL Injection via Gridsquare POST Parameter
Title source: llmDescription
An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function.
References (3)
Core 3
Core References
Exploit, Third Party Advisory
https://github.com/XY20130630/Cloudlog/security/advisories/GHSA-4r9r-3r3q-jg44
Release Notes
https://github.com/magicbug/Cloudlog/releases/tag/2.7.6
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
17.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
magicbug/cloudlog
< 2.7.6
Published
Nov 14, 2025
Tracked Since
Feb 18, 2026