PT-2021-11828 · Librenms · Librenms
Jellyfrog
·
Published
2021-02-08
·
Updated
2021-05-06
·
CVE-2020-35700
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
LibreNMS versions prior to 21.1.0
Description:
A second-order SQL injection issue in the Top Devices dashboard widget of LibreNMS allows remote authenticated attackers to execute arbitrary SQL commands via the
sort order parameter against the "/ajax/form/widget-settings" endpoint.Recommendations:
For versions prior to 21.1.0, update to version 21.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/ajax/form/widget-settings" endpoint or disabling the
sort order parameter in the Top Devices dashboard widget until a patch is available.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms