Vulnerability Details CVE-2020-35700
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-35700
-
cpe:2.3:a:librenms:librenms:-
-
cpe:2.3:a:librenms:librenms:0.1
-
cpe:2.3:a:librenms:librenms:1.19
-
cpe:2.3:a:librenms:librenms:1.20
-
cpe:2.3:a:librenms:librenms:1.20.1
-
cpe:2.3:a:librenms:librenms:1.21
-
cpe:2.3:a:librenms:librenms:1.22
-
cpe:2.3:a:librenms:librenms:1.22.01
-
cpe:2.3:a:librenms:librenms:1.23
-
cpe:2.3:a:librenms:librenms:1.24
-
cpe:2.3:a:librenms:librenms:1.25
-
cpe:2.3:a:librenms:librenms:1.26
-
cpe:2.3:a:librenms:librenms:1.27
-
cpe:2.3:a:librenms:librenms:1.28
-
cpe:2.3:a:librenms:librenms:1.29
-
cpe:2.3:a:librenms:librenms:1.30
-
cpe:2.3:a:librenms:librenms:1.30.01
-
cpe:2.3:a:librenms:librenms:1.31
-
cpe:2.3:a:librenms:librenms:1.31.01
-
cpe:2.3:a:librenms:librenms:1.31.02
-
cpe:2.3:a:librenms:librenms:1.31.03
-
cpe:2.3:a:librenms:librenms:1.32
-
cpe:2.3:a:librenms:librenms:1.32.01
-
cpe:2.3:a:librenms:librenms:1.33
-
cpe:2.3:a:librenms:librenms:1.33.01
-
cpe:2.3:a:librenms:librenms:1.34
-
cpe:2.3:a:librenms:librenms:1.35
-
cpe:2.3:a:librenms:librenms:1.36
-
cpe:2.3:a:librenms:librenms:1.36.01
-
cpe:2.3:a:librenms:librenms:1.37
-
cpe:2.3:a:librenms:librenms:1.38
-
cpe:2.3:a:librenms:librenms:1.39
-
cpe:2.3:a:librenms:librenms:1.40
-
cpe:2.3:a:librenms:librenms:1.41
-
cpe:2.3:a:librenms:librenms:1.42
-
cpe:2.3:a:librenms:librenms:1.42.01
-
cpe:2.3:a:librenms:librenms:1.43
-
cpe:2.3:a:librenms:librenms:1.44
-
cpe:2.3:a:librenms:librenms:1.45
-
cpe:2.3:a:librenms:librenms:1.46
-
cpe:2.3:a:librenms:librenms:1.47
-
cpe:2.3:a:librenms:librenms:1.48
-
cpe:2.3:a:librenms:librenms:1.48.1
-
cpe:2.3:a:librenms:librenms:1.49
-
cpe:2.3:a:librenms:librenms:1.50
-
cpe:2.3:a:librenms:librenms:1.50.1
-
cpe:2.3:a:librenms:librenms:1.51
-
cpe:2.3:a:librenms:librenms:1.52
-
cpe:2.3:a:librenms:librenms:1.53
-
cpe:2.3:a:librenms:librenms:1.53.1
-
cpe:2.3:a:librenms:librenms:1.54
-
cpe:2.3:a:librenms:librenms:1.55
-
cpe:2.3:a:librenms:librenms:1.56
-
cpe:2.3:a:librenms:librenms:1.57
-
cpe:2.3:a:librenms:librenms:1.58
-
cpe:2.3:a:librenms:librenms:1.58.1
-
cpe:2.3:a:librenms:librenms:1.59
-
cpe:2.3:a:librenms:librenms:1.60
-
cpe:2.3:a:librenms:librenms:1.61
-
cpe:2.3:a:librenms:librenms:1.62
-
cpe:2.3:a:librenms:librenms:1.62.1
-
cpe:2.3:a:librenms:librenms:1.62.2
-
cpe:2.3:a:librenms:librenms:1.63
-
cpe:2.3:a:librenms:librenms:1.64
-
cpe:2.3:a:librenms:librenms:1.64.1
-
cpe:2.3:a:librenms:librenms:1.65
-
cpe:2.3:a:librenms:librenms:1.65.1
-
cpe:2.3:a:librenms:librenms:1.66
-
cpe:2.3:a:librenms:librenms:1.67
-
cpe:2.3:a:librenms:librenms:1.68
-
cpe:2.3:a:librenms:librenms:1.69
-
cpe:2.3:a:librenms:librenms:1.70.0
-
cpe:2.3:a:librenms:librenms:1.70.1