← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 13, 2026 · 19:16via CVEFeed

CVE-2020-15875 - LibreNMS SQL Injection Vulnerability

Brief

CVE ID : CVE-2020-15875

Published : Sept. 13, 2026, 7:16 p. m.

  • 1 hour, 36 minutes ago

Description : An issue was discovered in LibreNMS 1.

  • A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table. php API endpoint. This affects as-selection. inc. php, edit-ports. inc. php, alertlog-stats. inc. php, alerts. inc. php, eventlog. inc. php, inventory. inc. php, ix-list. inc.

php, ix-peers. inc. php, mempool-edit. inc. php, mempool. inc. php, poll-log. inc. php, processor-edit. inc. php, processor. inc. php, routing-edit. inc. php, sensors-common. inc. php, storage-edit. inc. php, storage. inc. php, and toner. inc. php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.

Read more on CVEFeed→