Impact
An authenticated attacker with regular user privileges can leverage a SQL injection in the searchPhrase parameter of the /ajax_table.php API endpoint to read all data stored in the LibreNMS database. The flaw arises because input is concatenated into a query without proper sanitization (C attacker to read all information that the database holds.
Affected Systems
LibreNMS version 1.65 is affected. The vulnerability is present in PHP files that generate tables, including as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php.
Risk and Exploitability
The CVSS base score is 5.0, indicating moderate severity. The EPSS score is < 1%, implying a low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires remote access to the web interface and an authenticated session with standard user rights. Because the SQL injection works via a public API endpoint, an attacker can first log in, send the crafted searchPhrase request, and read the database contents. There is no privilege escalation beyond the authenticated session, but the attacker can retrieve all stored data.
OpenCVE Enrichment