Description

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporated into an SQL statement and concatenated, resulting in a SQL injection vulnerability. An attacker may extract a whole database this way. Version 24.4.0 fixes the issue.

INFO

Published Date :

2024-04-22T22:10:50.221Z

Last Modified :

2024-08-02T02:13:39.173Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-32480 vulnerability.

Vendors Products
Librenms
  • Librenms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-32480.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact