CVE-2026-54237
- EPSS 0.56%
- Veröffentlicht 17.09.2026 20:14:10
- Zuletzt bearbeitet 24.09.2026 21:25:27
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input re...
CVE-2024-48249
- EPSS 0.43%
- Veröffentlicht 14.10.2024 15:15:13
- Zuletzt bearbeitet 27.05.2025 19:41:23
Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48251
- EPSS 0.55%
- Veröffentlicht 14.10.2024 15:15:13
- Zuletzt bearbeitet 17.10.2024 18:35:12
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48257
- EPSS 0.66%
- Veröffentlicht 14.10.2024 15:15:13
- Zuletzt bearbeitet 16.10.2024 14:24:43
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-8521
- EPSS 0.57%
- Veröffentlicht 07.09.2024 08:15:11
- Zuletzt bearbeitet 04.06.2025 16:56:10
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible t...