SQL Injection Vulnerability in LibreNMS by LibreNMS
CVE-2020-15876
8.8HIGH
What is CVE-2020-15876?
A remote authenticated attacker with normal privileges can exploit a SQL injection vulnerability in LibreNMS 1.65 through the sort parameter of the /ajax_table.php API endpoint. This flaw allows the attacker to access all data from the LibreNMS database, potentially compromising sensitive information. The vulnerability spans multiple components, including address-search.inc.php and eventlog.inc.php, leading to significant security risks for users relying on LibreNMS for network monitoring.
