CVE-2020-36947

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librenms:librenms:1.46:*:*:*:*:*:*:*

History

17 Jun 2026, 03:16

Type Values Removed Values Added
Summary
  • (es) LibreNMS 1.46 contiene una vulnerabilidad de inyección SQL autenticada en el endpoint de gráfico de contabilidad MAC que permite a atacantes remotos extraer información de la base de datos. Los atacantes pueden explotar la vulnerabilidad manipulando el parámetro 'sort' con técnicas de inyección SQL elaboradas para recuperar contenido sensible de la base de datos a través de inyección SQL ciega basada en tiempo.

02 Feb 2026, 19:48

Type Values Removed Values Added
References () https://community.librenms.org/ - () https://community.librenms.org/ - Product
References () https://github.com/librenms/librenms - () https://github.com/librenms/librenms - Product
References () https://www.exploit-db.com/exploits/49246 - () https://www.exploit-db.com/exploits/49246 - Exploit, Third Party Advisory, VDB Entry
References () https://www.librenms.org - () https://www.librenms.org - Product
References () https://www.vulncheck.com/advisories/librenms-mac-accounting-graph-authenticated-sql-injection - () https://www.vulncheck.com/advisories/librenms-mac-accounting-graph-authenticated-sql-injection - Third Party Advisory
First Time Librenms librenms
Librenms
CPE cpe:2.3:a:librenms:librenms:1.46:*:*:*:*:*:*:*

27 Jan 2026, 22:15

Type Values Removed Values Added
References () https://community.librenms.org/ - () https://community.librenms.org/ -

27 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 16:16

Updated : 2026-06-17 03:16


NVD link : CVE-2020-36947

Mitre link : CVE-2020-36947

CVE.ORG link : CVE-2020-36947


JSON object : View

Products Affected

librenms

  • librenms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')