CVE-2024-48251

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 89

Summary

CVE-2024-48251 is a newly disclosed vulnerability affecting Wavelog 1.8.5. An SQL injection vulnerability exists in Activated_gridmap_model.php's get_band_confirmed function. Attackers can exploit this issue by manipulating input in the band, sat, propagation, or mode parameters to execute malicious SQL queries, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. This vulnerability poses a significant risk to organizations using Wavelog 1.8.5 and should be addressed promptly by applying the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share