Medium severity6.5NVD Advisory· Published Jul 21, 2020· Updated Jun 17, 2026
CVE-2020-15873
CVE-2020-15873
Description
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
librenms/librenmsPackagist | < 1.65.1 | 1.65.1 |
Affected products
3- LibreNMS/LibreNMSdescription
Patches
Vulnerability mechanics
References
8- github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcac4envdPatchThird Party AdvisoryWEB
- github.com/librenms/librenms/pull/11923nvdPatchThird Party AdvisoryWEB
- research.loginsoft.com/bugs/blind-sql-injection-in-librenms/nvdExploitThird Party Advisory
- community.librenms.org/c/announcementsnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-g5r6-vrmx-9gwjghsaADVISORY
- github.com/librenms/librenms/compare/1.65...1.65.1nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15873ghsaADVISORY
- research.loginsoft.com/bugs/blind-sql-injection-in-librenmsghsaWEB
News mentions
0No linked articles in our index yet.