PT-2025-41825 · Librenms · Librenms
Gatekeeperbuster
·
Published
2025-10-13
·
Updated
2025-10-20
·
CVE-2025-62365
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS versions prior to 25.7.0
Description
LibreNMS, an open-source network monitoring system, contains a reflected cross-site scripting (XSS) issue. The
report this function within librenms/includes/functions.php exhibits improper filtering of the project issues parameter when using the htmlentities function in an anchor environment. This allows for the execution of malicious scripts. The vulnerable function is report this.Recommendations
Upgrade to LibreNMS version 25.7.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms