LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-28T16:32:12

Updated: 2024-08-05T00:42:03.588Z

Reserved: 2019-08-19T00:00:00

Link: CVE-2019-15230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-28T17:15:09.747

Modified: 2019-08-30T19:15:30.940

Link: CVE-2019-15230

cve-icon Redhat

No data.