An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
{ "source": "REFERENCES" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15874.json"