Vulnerabilities > Librenms > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-21 CVE-2020-15873 SQL Injection vulnerability in Librenms
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
network
low complexity
librenms CWE-89
6.5
2019-09-09 CVE-2019-10670 Cross-site Scripting vulnerability in Librenms
An issue was discovered in LibreNMS through 1.47.
network
low complexity
librenms CWE-79
6.1
2019-09-09 CVE-2019-10667 Information Exposure vulnerability in Librenms
An issue was discovered in LibreNMS through 1.47.
network
low complexity
librenms CWE-200
5.3
2019-08-28 CVE-2019-15230 Cross-site Scripting vulnerability in Librenms 1.54
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console.
network
low complexity
librenms CWE-79
5.4
2018-10-18 CVE-2018-18478 Cross-site Scripting vulnerability in Librenms
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and html/includes/forms/edit-dashboard.inc.php.
network
low complexity
librenms CWE-79
6.1
2017-11-09 CVE-2017-16759 Path Traversal vulnerability in Librenms
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
network
high complexity
librenms CWE-22
5.9