This week’s release introduces new detections for CVE-2025-64459 and CVE-2025-24893.
Key Findings
- CVE-2025-64459: Django versions prior to 5.1.14, 5.2.8, and 4.2.26 are vulnerable to SQL injection via crafted dictionaries passed to QuerySet methods and the
Q()class. - CVE-2025-24893: XWiki allows unauthenticated remote code execution through crafted requests to the SolrSearch endpoint, affecting the entire installation.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 7a47683eacce4abd870ab2c630698ff3 | N/A | XWiki – Remote Code Execution – CVE:CVE-2025-24893 2 | Log | Block | This is a new detection. |
| Cloudflare Managed Ruleset | ad5c52f6ca334ef4a844e5e5da8ba7e6 | N/A | Django SQLI – CVE:CVE-2025-64459 | Log | Block | This is a new detection. |
| Cloudflare Managed Ruleset | f3a89a84e3744021a2f8e9291b138b3e | N/A | NoSQL, MongoDB – SQLi – Comparison | Block | Block | Changed the description of the rule. |
Source: Cloudflare
Latest Posts
- Dynamics 365 Sales – Clone and share Sales Development agent configuration across teams [MC1296464]
![Dynamics 365 Sales - Clone and share Sales Development agent configuration across teams [MC1296464] 2 waves 7674915 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Copilot Studio – CLI support for Microsoft Copilot Studio [MC1296434]
![Microsoft Copilot Studio – CLI support for Microsoft Copilot Studio [MC1296434] 3 pexels pachon in motion 426015731 16655822](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Project Operations – Add support for Lookups on custom columns [MC1296292]
![Dynamics 365 Project Operations - Add support for Lookups on custom columns [MC1296292] 4 pexels ir solyanaya 197121 634548](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Power Automate – Support for normalized schema import for data ingestion [MC1296281]
![Microsoft Power Automate - Support for normalized schema import for data ingestion [MC1296281] 5 pexels cottonbro 4874232](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Dynamics 365 Sales - Clone and share Sales Development agent configuration across teams [MC1296464] 2 waves 7674915 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/waves-7674915_1920-150x150.webp)
![Microsoft Copilot Studio – CLI support for Microsoft Copilot Studio [MC1296434] 3 pexels pachon in motion 426015731 16655822](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pachon-in-motion-426015731-16655822-150x150.webp)
![Dynamics 365 Project Operations - Add support for Lookups on custom columns [MC1296292] 4 pexels ir solyanaya 197121 634548](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-ir-solyanaya-197121-634548-150x150.webp)
![Microsoft Power Automate - Support for normalized schema import for data ingestion [MC1296281] 5 pexels cottonbro 4874232](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-cottonbro-4874232-150x150.webp)
