PT-2024-34658 · Librenms · Librenms

Raphaelcss

+1

·

Published

2024-11-15

·

Updated

2024-11-20

·

CVE-2024-51494

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 24.10.0
Description A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the descr parameter when editing a device's port settings. This can lead to the execution of malicious code when the "Port Settings" page is visited, potentially compromising the user's session and allowing unauthorized actions.
Recommendations For versions prior to 24.10.0, update to version 24.10.0 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the "Port Settings" page or disabling the editing of device port settings until the update is applied. Avoid using the descr parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51494
GHSA-7663-37RG-C377

Affected Products

Librenms