PT-2022-25472 · Git+2 · Librenms+1

Murrant

·

Published

2022-11-20

·

Updated

2022-11-29

·

CVE-2022-4068

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue allows a user to enable their own account even if it was disabled by an admin, as long as the user still holds a valid session. Additionally, there is a problem with the sanitization of the username in the admin user overview, which enables an XSS attack. This attack allows an attacker with low privilege user access to execute arbitrary JavaScript in the context of an admin's account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4068
GHSA-F3HW-3H74-WR98

Affected Products

Librenms
Librenms/Librenms