{"id":"CVE-2026-54237","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54237","summary":"Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without…","details":"Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.","published":"2026-09-17T21:17:14.980","modified":"2026-09-17T21:17:14.980","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/wavelog/wavelog/commit/9661efa86eff4598bd1a7ad8ca4ec60e76b6fb25","label":"wavelog/wavelog@9661efa"},"references":[{"type":"WEB","url":"https://github.com/wavelog/wavelog/commit/9661efa86eff4598bd1a7ad8ca4ec60e76b6fb25"},{"type":"WEB","url":"https://github.com/wavelog/wavelog/pull/3228"},{"type":"WEB","url":"https://github.com/wavelog/wavelog/releases/tag/2.4.2"},{"type":"WEB","url":"https://github.com/wavelog/wavelog/security/advisories/GHSA-jxjv-chgm-rh36"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T21:17:14.980"}}