A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the getstationinfo()function located in the file /application/models/Oqrsmodel.php. The vulnerability is exploitable via the stationid parameter.