vendor:
LibreNMS
by:
Askar
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: LibreNMS
Affected Version From: v1.46
Affected Version To: v1.46
Patch Exists: YES
Related CWE: CVE-2018-20434
CPE: 2.3:a:librenms:librenms:1.46
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04 / PHP 7.2.10
2018
LibreNMS v1.46 authenticated Remote Code Execution
LibreNMS is an open source network monitoring system. A vulnerability in LibreNMS v1.46 allows an authenticated user to execute arbitrary code on the server. This is due to the lack of input validation in the 'community' parameter of the 'addhost' page. An attacker can craft a malicious payload and inject it into the 'community' parameter to execute arbitrary code on the server.
Mitigation:
Upgrade to LibreNMS v1.47 or later.