SQL Injection Vulnerability in LibreNMS by LibreNMS
CVE-2020-15875
5MEDIUM
What is CVE-2020-15875?
A vulnerability exists in LibreNMS version 1.65 that allows a remote authenticated attacker to exploit a SQL injection flaw. By manipulating the searchPhrase parameter in the /ajax_table.php API endpoint, attackers with normal privileges can access and extract sensitive information from the entire LibreNMS database. The vulnerability affects multiple scripts within the application, potentially compromising the security of user data.
Affected Version(s)
LibreNMS 0 < 1.65.1
