An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-09-09T13:01:21

Updated: 2024-08-04T22:32:00.839Z

Reserved: 2019-03-31T00:00:00

Link: CVE-2019-10671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-09T14:15:11.740

Modified: 2019-09-10T15:28:20.113

Link: CVE-2019-10671

cve-icon Redhat

No data.