Command Injection Vulnerability in LibreNMS by LibreNMS
CVE-2020-15874
8.8HIGH
What is CVE-2020-15874?
A command injection vulnerability in LibreNMS version 1.65 allows remote authenticated users to execute arbitrary shell commands through the compromised /graph.php API endpoint. This vulnerability poses a serious risk, as it could enable attackers with normal privileges to manipulate the system and potentially compromise sensitive data.
