PT-2022-25472 · Git+2 · Librenms+1
Murrant
·
Published
2022-11-20
·
Updated
2022-11-29
·
CVE-2022-4068
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
The issue allows a user to enable their own account even if it was disabled by an admin, as long as the user still holds a valid session. Additionally, there is a problem with the sanitization of the username in the admin user overview, which enables an XSS attack. This attack allows an attacker with low privilege user access to execute arbitrary JavaScript in the context of an admin's account.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librenms
Librenms/Librenms