CVE-2018-20678: SQL Injection
Published Mar 28, 2019
·Updated
LibreNMS through 1.47 allows SQL injection via the html/ajaxtable.php sort[hostname] parameter, exploitable by authenticated users during a search.
Affected Software
2 affected componentsFixes available
composer/librenms/librenms<=1.47
1.65
librenms librenms<=1.47
Event History
Mar 28, 2019
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
May 14, 2022
Advisory Published
01:14 AM
Frequently Asked Questions
1
What is CVE-2018-20678?
CVE-2018-20668 is a vulnerability in LibreNMS through version 1.47 that allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.
2
How severe is CVE-2018-20678?
CVE-2018-20678 has a severity rating of 8.8 (high).
3
How can CVE-2018-20678 be exploited?
CVE-2018-20678 can be exploited by authenticated users during a search using the html/ajax_table.php sort[hostname] parameter.
4
What is the affected software for CVE-2018-20678?
The affected software for CVE-2018-20678 is LibreNMS through version 1.47.
5
Is there a fix available for CVE-2018-20678?
Yes, the remedy for CVE-2018-20678 is to update to version 1.65 of LibreNMS.