CVE-2019-12463

HIGH

LibreNMS 1.50.1-1.53 - Authenticated RRDtool Injection via Graph Parameter

Title source: llm
STIX 2.1

Description

An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php and html/graph-realtime.php scripts. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, disclosing file content, denial of service, or writing arbitrary files. NOTE: relative to CVE-2019-10665, this requires authentication and the pathnames differ.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0139
EPSS Percentile 68.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74 CWE-116
Status published
Products (2)
librenms/librenms 1.50.1 - 1.53
librenms/librenms 1.50.1 - 1.53Packagist
Published Sep 09, 2019
Tracked Since Feb 18, 2026