LibreNMS code exec via abuse of WHOIS functionality (requires admin access on the web UI):
Uncategorized
1
Posts
1
Posters
0
Views
-
LibreNMS code exec via abuse of WHOIS functionality (requires admin access on the web UI):
LibreNMS < 26.3.0 Authenticated RCE & XSS
By searching for unsafe patterns and function calls, we discovered authenticated XSS and RCE vulnerabilities in LibreNMS.
Research Blog | Project Black (projectblack.io)
-
R relay@relay.infosec.exchange shared this topic