CVE-2025-65093 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was id…
Medium CVSS: 5.5

CVE-2025-65093

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly into an SQL query without proper sanitization or parameter binding, allowing an attacker to manipulate the query logic and infer data from the database through conditional responses. This issue has been patched in version 25.11.0.
Vendor
Librenms
Product
Librenms
CWE
CWE-89
Yayın Tarihi
2025-11-18 23:15:57
Güncelleme
2025-11-20 16:18:22
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar