RULE(RULE ID:338473)

Rule General Information
Release Date: 2024-10-22
Rule Name: Cloudlog delete_oqrs_line SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Cloudlog is a self-hosted PHP application. An unauthorized SQL injection vulnerability exsits in its delete_oqrs_line_port endpoint, which can be exploited by an unauthenticated, remote attacker to gain access to data in the database or even gain system privileges on the server.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.