← volver
CVE-2024-51494

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php

CVSS 4.8 MEDIUMEPSS 0.4%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.8EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 nov 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port settings. This vulnerability can lead to the execution of malicious code when the "Port Settings" page is visited, potentially compromising the user's session and allowing unauthorized actions. This vulnerability is fixed in 24.10.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Productos afectados
librenms · librenms

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →