mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 01:04:30 +00:00
943 B
943 B
CVE-2020-15873
Description
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
POC
Reference
- https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/
- https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/