वीकनेस
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
संदर्भ
- https://community.librenms.org/c/announcements
- https://github.com/librenms/librenms/compare/1.65...1.65.1
- https://github.com/librenms/librenms/releases/tag/1.65.1
- https://shielder.it/blog
- https://www.shielder.com/advisories/librenms-graph-authenticated-command-injection/
- https://www.shielder.com/advisories/librenms-graph-authenticated-command-injection/
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।