← Back to CVE List

CVE-2024-32480

Published: 2024-04-22T23:15Z
Last Modified: 2025-01-02T21:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporated into an SQL statement and concatenated, resulting in a SQL injection vulnerability. An attacker may extract a whole database this way. Version 24.4.0 fixes the issue. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt