LibreNMS 在 26.8.0 之前版本中存在一个参数注入漏洞,位于 参数中。已认证的 attacker 可以通过突破双引号转义机制,注入任意的 rrdtool 参数。攻击者可以注入 和 参数,从而读取未授权设备上的 RRD 文件;或者通过换行符注入执行任意 rrdtool 命令,绕过针对每个设备的授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet