PT-2026-4926 · Librenms · Librenms
Hodorsec
·
Published
2026-01-27
·
Updated
2026-02-02
·
CVE-2020-36947
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS version 1.46
Description
LibreNMS version 1.46 contains an authenticated SQL injection issue in the MAC accounting graph endpoint. This allows remote attackers to extract database information by manipulating the
sort parameter with crafted SQL injection techniques, enabling time-based blind SQL injection. The affected API endpoint is the MAC accounting graph endpoint.Recommendations
Apply a fix or patch for LibreNMS version 1.46 to address the SQL injection issue in the MAC accounting graph endpoint. As a temporary workaround, restrict access to the MAC accounting graph endpoint or sanitize the
sort parameter to prevent SQL injection attacks.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms