In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade librenms/librenms to version 26.5.0 or higher.
librenms/librenms is a fully featured network monitoring system that provides a wealth of features and device support.
Affected versions of this package are vulnerable to Command Injection in the AboutController process when the snmpget configuration parameter is manipulated to point to a malicious executable file on the system. An attacker can execute arbitrary system commands with web server privileges by updating the configuration and accessing the /about endpoint. This is only exploitable if the attacker has administrator credentials and the ability to place a malicious executable on the server.