CVE-2020-36947

Source
https://cve.org/CVERecord?id=CVE-2020-36947
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36947.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36947
Aliases
Published
2026-01-27T16:16:12.040Z
Modified
2026-07-08T17:56:26.399147Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

References

Affected packages

Git / github.com/librenms/librenms

Affected ranges

Type
GIT
Repo
https://github.com/librenms/librenms
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:librenms:librenms:1.46:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.46"
        },
        {
            "last_affected": "1.46"
        }
    ]
}

Affected versions

1.*
1.46

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36947.json"