CVE-2020-35700: SQL Injection
(updated )
A second-order SQL injection issue in Widgets/TopDevicesController.php
(aka the Top Devices dashboard widget) of LibreNMS allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings
endpoint.
References
Detect and mitigate CVE-2020-35700 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →