In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2024-04-24T20:18:01Z",
"nvd_published_at": "2020-07-21T17:15:00Z",
"severity": "MODERATE"
}