Vulnerabilities & PatchesEmerging1 src
CVE-2020-15875 - LibreNMS SQL Injection Vulnerability
CVE ID : CVE-2020-15875
Published : Sept. 13, 2026, 7:16 p. m.
• 1 hour, 36 minutes ago
Description : An issue was discovered in LibreNMS 1. 65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table. php API endpoint. This affects as-selection. inc. php, edit-ports. inc. php, alertlog-stats. inc. php, alerts. inc. php, eventlog. inc. php, inventory. inc. php, ix-list. inc.
php, ix-peers. inc. php, mempool-edit. inc. php, mempool. inc. php, poll-log. inc. php, processor-edit. inc. php, processor. inc. php, routing-edit. inc. php, sensors-common. inc. php, storage-edit. inc. php, storage. inc. php, and toner. inc. php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.