First published: Mon Feb 08 2021(Updated: )
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Librenms Librenms | <21.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-35700.
The title of this vulnerability is 'A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0'.
The affected software for this vulnerability is LibreNMS version up to but excluding 21.1.0.
The severity of this vulnerability is high with a CVSS score of 8.8.
An attacker can exploit this vulnerability by sending malicious SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.