CyberRota Analysis
AI-GeneratedWavelog versions 1.8 to 2.4.2 are vulnerable due to the exposure of critical installation scripts without proper access controls, allowing remote unauthenticated attackers to manipulate log files and PHP configuration files. This vulnerability can lead to arbitrary code execution on the server, posing a significant risk to the integrity and confidentiality of the affected systems. Organizations using Wavelog should prioritize upgrading to version 2.4.2 to mitigate this critical security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.