CVE-2019-12465: SQL Injection
Published Sep 9, 2019
·Updated
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajaxrulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajaxrulesuggest.php?debug=1&term= request.
Affected Software
1 affected component
librenms librenms<1.53
Event History
Sep 9, 2019
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in LibreNMS?
The vulnerability ID is CVE-2019-12465.
2
What is the severity level of CVE-2019-12465?
The severity level of CVE-2019-12465 is high.
3
What is the affected version of LibreNMS?
LibreNMS versions up to exclusive 1.53 are affected.
4
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-89.
5
Is there a reference link for more information about this vulnerability?
Yes, you can find more information about this vulnerability at the following link: https://www.darkmatter.ae/xen1thlabs/librenms-sql-injection-vulnerability-xl-19-024/