Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade librenms/librenms
to version 24.10.0 or higher.
librenms/librenms is a fully featured network monitoring system that provides a wealth of features and device support.
Affected versions of this package are vulnerable to Command Injection via the shell_exec()
function in AboutController.php
. A malicious device whose hostname includes shell metacharacters can allow arbitrary code to be run on the underlying OS when a legitimate user runs the PollDevice
job. A user who can modify configuration settings can implant the malicious file on the target system.