PT-2024-34159 · Librenms · Librenms
Raphaelcss
+1
·
Published
2024-11-15
·
Updated
2026-02-18
·
CVE-2024-50350
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
LibreNMS versions prior to 24.10.0
Description:
A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the
name parameter when creating a new Port Group. This results in the execution of malicious code when the "Port Settings" page is visited after the affected Port Group is added to a device, potentially compromising user sessions and allowing unauthorized actions.Recommendations:
For versions prior to 24.10.0, update to version 24.10.0 to fix the vulnerability. As a temporary workaround, consider restricting access to the "Port Settings" page and avoiding the use of the
name parameter when creating new Port Groups until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms