CVE-2020-15873
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
21/07/2020
Last modified:
23/07/2020
Description
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | 1.65.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://community.librenms.org/c/announcements
- https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcac4e
- https://github.com/librenms/librenms/compare/1.65...1.65.1
- https://github.com/librenms/librenms/pull/11923
- https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/