{"id":"CVE-2020-15873","aliases":["GHSA-g5r6-vrmx-9gwj"],"url":"https://o3.security/vulnerability/CVE-2020-15873","summary":"LibreNMS SQL Injection vulnerability","details":"In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.","published":"2020-07-21T17:15:12.060Z","modified":"2026-07-08T12:05:38.208028Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.0222,"percentile":0.81123,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"librenms/librenms","fixedVersion":"1.65.1"}],"fix":{"url":"https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcac4e","label":"librenms/librenms@8f3a29c"},"references":[{"type":"ADVISORY","url":"https://community.librenms.org/c/announcements"},{"type":"ADVISORY","url":"https://github.com/librenms/librenms/compare/1.65...1.65.1"},{"type":"FIX","url":"https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcac4e"},{"type":"FIX","url":"https://github.com/librenms/librenms/pull/11923"},{"type":"EVIDENCE","url":"https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:38.208028Z"}}