Impact
A classic SQL injection flaw was discovered in LibreNMS 1.65, where an attacker who can log in with normal privileges can craft input for the sort parameter in the /ajax_table.php API endpoint. By doing so the attacker can extract the entire content of the LibreNMS database, exposing network asset data, configuration details, system logs, and other sensitive information.
Affected Systems
All installations running LibreNMS version 1.65 before the 1.65.1 release are affected. The flaw is present in many include files used throughout the interface. Versions newer than or equal to 1.65.1 contain the fix, and no additional product lines are listed.
Risk and Exploitability
At the time of disclosure, the CVSS score was 8.8 and the EPSS score was below 1%. The vulnerability is not listed in CISA KEV. Because it requires only normal authenticated access, any user that can log in can send a crafted HTTP request to the vulnerable endpoint. No public exploit was reported, but the impact is a total loss of confidentiality of the database.
OpenCVE Enrichment