Impact
LibreNMS, an auto‑discovering PHP/MySQL/SNMP based network monitoring tool, contains a reflected XSS flaw that can be triggered through the email field in forms and URLs. The vulnerability allows an attacker to inject arbitrary JavaScript that executes in the victim’s browser, potentially enabling session hijacking, credential theft, or defacement. The weakness is classified as CWE‑79 and is measured at a CVSS score of 5.3.
Affected Systems
All LibreNMS releases up to and including 25.12.0 are vulnerable. The issue was addressed in version 26.2.0, so any deployment with the main LibreNMS application before that release must consider an upgrade. Vendors listed under librenms:librenms are affected if their installed version is older than 26.2.0.
Risk and Exploitability
The CVSS rating of 5.3 indicates moderate severity, while the EPSS score of less than 1% points to a very low likelihood of active exploitation. The flaw is not recorded in the CISA Known Exploited Vulnerabilities catalog. Attackers would typically need to entice a user to visit a page containing a malicious email string or to post such a string into the application, meaning the vector is user‑based interaction with the web interface and does not require privileged credentials.
OpenCVE Enrichment
Github GHSA