Impact
LibreNMS, before version 26.3.1, contains a stored cross‑site scripting flaw in legacy PHP templates that output data from SNMP and syslog without escaping. An attacker who can control a monitored network device can inject arbitrary JavaScript into SNMP interface descriptions or syslog program fields; the injected script runs in a browser when an authenticated user views the affected pages, potentially leading to session hijacking or data theft.
Affected Systems
The affected product is LibreNMS, with all releases prior to version 26.3.1 being vulnerable. The product is supplied by the vendor librenms, as identified by the associated CNA.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating significant severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to control a monitored network device to supply malicious SNMP or syslog data; successful exploitation also requires an authenticated user to view the vulnerable pages. Because the flaw can be triggered by simply inserting malicious text into device descriptions or syslog fields, the barrier to exploit remains low for an attacker who can influence these inputs.
OpenCVE Enrichment