logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-32461

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-32461

Description:
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. With this vulnerability, an attacker can exploit a SQL injection time based vulnerability to extract all data from the database, such as administrator credentials. Version 24.4.0 contains a patch for the vulnerability.
Last updated date:
01/02/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/02/2025
Reference url to background

https://doc.clickup.com/9013166444/p/h/8ckm0bc-53/16811991bb5fff6

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/02/2025
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy