PT-2026-4926 · Librenms · Librenms

Hodorsec

·

Published

2026-01-27

·

Updated

2026-02-02

·

CVE-2020-36947

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreNMS version 1.46
Description LibreNMS version 1.46 contains an authenticated SQL injection issue in the MAC accounting graph endpoint. This allows remote attackers to extract database information by manipulating the sort parameter with crafted SQL injection techniques, enabling time-based blind SQL injection. The affected API endpoint is the MAC accounting graph endpoint.
Recommendations Apply a fix or patch for LibreNMS version 1.46 to address the SQL injection issue in the MAC accounting graph endpoint. As a temporary workaround, restrict access to the MAC accounting graph endpoint or sanitize the sort parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-36947
GHSA-QP2J-V5JG-HG68

Affected Products

Librenms