CVE-2020-15873
MEDIUMLibrenms < 1.65.1 - SQL Injection
Title source: ruleDescription
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
Exploits (1)
References (5)
Scores
CVSS v3
6.5
EPSS
0.0753
EPSS Percentile
91.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (2)
librenms/librenms
< 1.65.1
librenms/librenms
0 - 1.65.1Packagist
Published
Jul 21, 2020
Tracked Since
Feb 18, 2026