Vulnerability Description
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Librenms | Librenms | < 1.65.1 |
Related Weaknesses (CWE)
References
- https://community.librenms.org/c/announcementsRelease NotesVendor Advisory
- https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcPatchThird Party Advisory
- https://github.com/librenms/librenms/compare/1.65...1.65.1Third Party Advisory
- https://github.com/librenms/librenms/pull/11923PatchThird Party Advisory
- https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/ExploitThird Party Advisory
- https://community.librenms.org/c/announcementsRelease NotesVendor Advisory
- https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcPatchThird Party Advisory
- https://github.com/librenms/librenms/compare/1.65...1.65.1Third Party Advisory
- https://github.com/librenms/librenms/pull/11923PatchThird Party Advisory
- https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/ExploitThird Party Advisory
FAQ
What is CVE-2020-15873?
CVE-2020-15873 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
How severe is CVE-2020-15873?
CVE-2020-15873 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15873?
Check the references section above for vendor advisories and patch information. Affected products include: Librenms Librenms.