Directory Traversal Vulnerability in LibreNMS by LibreNMS
CVE-2019-12464
7.5HIGH
What is CVE-2019-12464?
An issue was identified in LibreNMS version 1.50.1 where an authenticated user can exploit a directory traversal vulnerability through the /pdf.php file. By supplying a partial filename to the report parameter, the attacker can trigger local file inclusion, which may lead to unauthorized code execution on the server.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved