SQL Injection Vulnerability in LibreNMS Network Monitoring Tool
CVE-2025-65093
5.5MEDIUM
What is CVE-2025-65093?
A boolean-based blind SQL injection vulnerability exists in the LibreNMS application at the /ajax_output.php endpoint. This flaw allows attackers to directly manipulate SQL queries by injecting malicious input into the hostname parameter, which is not properly sanitized. As a result, attackers could infer sensitive data from the database through crafted conditional responses. This vulnerability was addressed in LibreNMS version 25.11.0, emphasizing the importance of secure coding practices to prevent direct SQL manipulation.
Affected Version(s)
librenms < 25.11.0
