CVE-2019-10666

Source
https://cve.org/CVERecord?id=CVE-2019-10666
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10666.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10666
Published
2019-09-09T13:15:11.357Z
Modified
2026-07-08T20:05:18.483120Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attacker can leverage this to execute PHP code from the included file. Exploitation of these scripts is made difficult by additional text being appended (typically .inc.php), which means an attacker would need to be able to control both a filename and its content on the server. However, exploitation can be achieved as demonstrated by the csv.php?report=../ substring.

References

Affected packages

Git / github.com/librenms/librenms

Affected ranges

Type
GIT
Repo
https://github.com/librenms/librenms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.47"
        }
    ]
}

Affected versions

0.*
0.1
1.*
1.19
1.20
1.21
1.25
1.26
1.27
1.28
1.31.01
1.31.02
1.31.03
1.32
1.33
1.35
1.36
1.37
1.38
1.39
1.40
1.41
1.42
1.42.01
1.43
1.44
1.45
1.46
1.47
Other
201505
201506
201507
201508
201509
201510
201511
201512
201601
201602
201603
201604
201605
201606
201607
201608
20160828
201609

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10666.json"