CNNVD-202511-1959 Information
CNNVD ID
CNNVD-202511-1959
Related CVE
- CNNVD Published: 2025-11-18
Description (Chinese)
LibreNMS是LibreNMS社区的一套基于PHP和MySQL的开源网络监控系统。该系统具有自定义警报、自动发现网络环境和自动更新等特点。 LibreNMS 25.11.0之前版本存在SQL注入漏洞,该漏洞源于hostname参数未正确清理或绑定,可能导致SQL注入攻击。
Description (English)
LibreNMS is an open-source network monitoring system based on PHP and MySQL for the LibreNMS community. The system has features such as custom alerts, automatic discovery of the network environment and automatic updating. The previous version of LibreNMS 25.11.0 had an injection loophole in SQL, which stemmed from the miscleaning or binding of the hostname parameters, which could lead to an SQL injection attack.
Hazard Level
High
Vulnerability Type
SQL注入
Affected Vendor
LibreNMS
Published
2025-11-18
Last Modified
2026-02-24
References
https://github.com/librenms/librenms/security/advisories/GHSA-6pmj-xjxp-p8g9 https://access.redhat.com/security/cve/cve-2025-65093
Patch
https://github.com/librenms/librenms/releases
Share on: