CVE-2024-48251
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-48251 is a newly disclosed vulnerability affecting Wavelog 1.8.5. An SQL injection vulnerability exists in Activated_gridmap_model.php's get_band_confirmed function. Attackers can exploit this issue by manipulating input in the band, sat, propagation, or mode parameters to execute malicious SQL queries, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. This vulnerability poses a significant risk to organizations using Wavelog 1.8.5 and should be addressed promptly by applying the necessary patches or updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wavelog