← back
CVE-2024-50352

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.php

CVSS 4.8 MEDIUMEPSS 36.7%CWE-79
In short

LibreNMS allows authenticated users to inject malicious code into the Services section, which gets stored and executed in other users' browsers when they view the page. This could let attackers steal session data or perform actions as other users.

Technical detail

Stored XSS vulnerability in the Services page of Device Overview exists in the 'name' parameter when adding a service. An authenticated attacker can inject arbitrary JavaScript that persists in the database and executes in victims' browsers with their privileges, potentially leading to session hijacking or unauthorized device management actions.

Summary generated and translated by AI from the official description.
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
librenms · librenms

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →