Tony Murray
50 exploits
Active since Jul 2020
LibreNMS < 1.65.1 - Authenticated SQL Injection via device_id POST Parameter
CVSS 6.5
LibreNMS < 24.9.0 - Self Cross-Site Scripting in Alert Template Name
CVSS 3.5
LibreNMS < 26.2.0 - Reflected Cross-Site Scripting via Email Field
CVSS 6.1
LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
CVSS 9.1
LibreNMS < 26.2.0 - Authenticated Stored Cross-Site Scripting in Alert Rules Workflow
CVSS 4.3
LibreNMS < 26.2.0 - Authenticated Time-Based Blind SQL Injection via Address Parameter
CVSS 8.8
LibreNMS < 26.2.0 - Authenticated Stored Cross-Site Scripting via Device Group Name
CVSS 4.8
LibreNMS < 26.2.0 - Authenticated Stored Cross-Site Scripting via Port Group Name
CVSS 4.8
LibreNMS 24.10.0-26.1.1 - Stored XSS
CVSS 5.4
LibreNMS <1.65.1 - Privilege Escalation
CVSS 8.8
LibreNMS < 21.1.0 - Authenticated SQL Injection via Top Devices Widget sort_order Parameter
CVSS 8.8
LibreNMS < 21.10.2 - Cross-Site Scripting via Widget Title
CVSS 6.1
LibreNMS < 22.4.0 - Cross-Site Scripting via GraylogController
CVSS 6.1
librenms < 22.9.0 - Stored Cross-Site Scripting
CVSS 5.4
librenms < 22.10.0 - Stored Cross-Site Scripting
CVSS 6.1
librenms/librenms <22.10.0 - Deserialization
CVSS 8.8
GitHub librenms/librenms <22.10.0 - XSS
CVSS 6.1
librenms < 22.10.0 - Stored Cross-Site Scripting
CVSS 5.4
librenms < 22.10.0 - Stored Cross-Site Scripting
CVSS 5.4
LibreNMS <= 22.10.0 - Account Re-enablement and XSS
CVSS 5.4
librenms < 22.10.0 - Cross-Site Scripting
CVSS 4.8
librenms/librenms <22.10.0 - Info Disclosure
CVSS 9.8
librenms < 23.8.0 - Reflected Cross-Site Scripting
CVSS 5.4
LibreNMS < 23.11.0 - Authenticated Device Enumeration via graph.php
CVSS 4.3
LibreNMS < 23.11.0 - Stored Cross-Site Scripting in Device Group Popups
CVSS 6.3