PT-2024-34159 · Librenms · Librenms

Raphaelcss

+1

·

Published

2024-11-15

·

Updated

2026-02-18

·

CVE-2024-50350

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: LibreNMS versions prior to 24.10.0
Description: A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the name parameter when creating a new Port Group. This results in the execution of malicious code when the "Port Settings" page is visited after the affected Port Group is added to a device, potentially compromising user sessions and allowing unauthorized actions.
Recommendations: For versions prior to 24.10.0, update to version 24.10.0 to fix the vulnerability. As a temporary workaround, consider restricting access to the "Port Settings" page and avoiding the use of the name parameter when creating new Port Groups until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-50350
GHSA-XH4G-C9P6-5JXG

Affected Products

Librenms