← Back

CVE-2019-10671

nvd nist
Published: Sep 9, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.

Affected (1)

Products: Librenms: Librenms
1 product
Librenms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.47

References (2)

Timeline

No history available yet.