ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-35700”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-35700
Published
2021-02-08
CVSS:
8.8
ShadowTrackr CVSS:
6.8
Summary:
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.