A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.
{ "nvd_published_at": "2021-02-08T09:15:00Z", "github_reviewed_at": "2021-04-05T20:39:08Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-89" ] }