CVE-2024-45999: Magicbug Cloudlog
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.
Affected products
- Magicbug Cloudlog: up to and including 2.6.15
Published 2024-10-01. Last modified 2026-06-17.