CVE-2025-26047
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Published Feb 28, 2025
Updated: Mar 6, 2025
CWE ID 89
Summary
CVE-2025-26047 is a newly disclosed vulnerability affecting Loggrove version 1.0. The issue lies in the read.py file where SQL Injection vulnerabilities have been discovered. An attacker can exploit this flaw by injecting malicious SQL commands into the input data, potentially gaining unauthorized access to sensitive information or even taking control of the underlying database. This vulnerability poses a serious risk, and affected users are advised to upgrade to the latest version of Loggrove as soon as possible to mitigate the danger.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.