Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
https://github.com/wavelog/wavelog/commit/0bf2675d93602b591850790c8fcfced886eca423
https://chiggerlor.substack.com/p/unauthenticated-sql-injection-in