LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. This vulnerability is fixed in 24.9.0.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Librenms
Librenms librenms |
|
CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Librenms
Librenms librenms |
|
Metrics |
ssvc
|
Tue, 01 Oct 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. This vulnerability is fixed in 24.9.0. | |
Title | Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-alert-rules.php | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-01T20:27:32.224Z
Updated: 2024-10-02T13:01:42.584Z
Reserved: 2024-09-25T21:46:10.928Z
Link: CVE-2024-47525
Vulnrichment
Updated: 2024-10-02T13:01:38.099Z
NVD
Status : Analyzed
Published: 2024-10-01T21:15:07.520
Modified: 2024-10-07T19:08:18.707
Link: CVE-2024-47525
Redhat
No data.