GHSA-w5r2-gvgf-mpm8

    Dashboard / Vulnerabilities / GHSA-w5r2-gvgf-mpm8

    GHSA-w5r2-gvgf-mpm8

    Published: 11 Oct 2019Last Modified: 16 Feb 2024

    Summary: Improper Encoding or Escaping of Output and Injection in LibreNMS

    Details: An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php and html/graph-realtime.php scripts. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, disclosing file content, denial of service, or writing arbitrary files. NOTE, relative to CVE-2019-10665, this requires authentication and the pathnames differ.

    Affected packages

    Package

    Name: librenms/librenms

    Purl: pkg:composer/librenms/librenms

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.50.1
    Fixed -1.53

    Affected versions

    1.50.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High