Vulnerabilities > Wavelog

DATE CVE VULNERABILITY TITLE RISK
2024-10-14 CVE-2024-48251 SQL Injection vulnerability in Wavelog 1.8.5
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
network
low complexity
wavelog CWE-89
critical
9.8
2024-10-14 CVE-2024-48257 SQL Injection vulnerability in Wavelog 1.8.5
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
network
low complexity
wavelog CWE-89
critical
9.8