HIGH
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint
Published Feb 8, 2021
8.8
HIGHCVSS 3.1
EPSS 2.34%
Description
Affected products
Remediation
References (8)
Change history (0)
No recorded changes yet.