CVE-2019-12464: Path Traversal
Published Sep 9, 2019
·Updated
An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.
Affected Software
1 affected component
librenms librenms=1.50.1
Event History
Sep 9, 2019
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-12464.
2
What is the severity level of CVE-2019-12464?
CVE-2019-12464 has a severity level of high (7.5).
3
What is the description of CVE-2019-12464?
CVE-2019-12464 is a directory traversal vulnerability in LibreNMS 1.50.1 that allows an authenticated user to perform a local file inclusion resulting in code execution.
4
Which version of LibreNMS is affected by CVE-2019-12464?
LibreNMS version 1.50.1 is affected by CVE-2019-12464.
5
How can I fix CVE-2019-12464?
To fix CVE-2019-12464, it is recommended to upgrade to a newer version of LibreNMS that has patched the vulnerability.