SQL injection in LibreNMS - CVE-2025-65093
Published: April 24, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to SQL injection in the hostname parameter of the /ajax_output.php endpoint when handling discovery requests. A remote privileged user can send a specially crafted request to disclose sensitive information and modify data.
The issue is boolean-based blind SQL injection in the discovery functionality.