HIGH
An issue was discovered in LibreNMS through 1.47
Published Sep 9, 2019
7.2
HIGHCVSS 3.1
EPSS 80.69%
Description
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does not escape a number of command line syntax characters such as ` (backtick), allowing an attacker to inject commands into the variable $rrd_cmd, which gets executed via passthru().
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://packetstormsecurity.com/files/154391/LibreNMS-Collectd-Command-Injection.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://www.darkmatter.ae/xen1thlabs/librenms-command-injection-vulnerability-xl-19-017/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/154391/LibreNMS-Collectd-Command-Injection.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://www.darkmatter.ae/xen1thlabs/librenms-command-injection-vulnerability-xl-19-017/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2019
Updated Aug 4, 2024
Reserved Mar 31, 2019
Link CVE-2019-10669
CISA Vulnrichment
Updated n/a