PT-2025-42519 · Librenms · Librenms

Published

2025-10-16

·

Updated

2025-10-17

·

CVE-2025-62411

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 25.10.0
Description LibreNMS, a network monitoring system, contains a Stored Cross-Site Scripting (XSS) issue in the Alert Transports management functionality. The Transport name field is stored without proper validation and rendered in the Transports column of the Alert Rules page, leading to arbitrary JavaScript execution in an administrator’s browser. The injection point is the Transport name field in the '/alert-transports' API endpoint, and the execution point is the Transports column in the '/alert-rules' API endpoint. The vulnerability affects only administrator accounts.
Recommendations Update LibreNMS to version 25.10.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62411
GHSA-FRC6-PWGR-C28W

Affected Products

Librenms