PT-2025-52726 · Librenms · Librenms

Zdi-Disclosures

·

Published

2025-12-22

·

Updated

2026-01-02

·

CVE-2025-68614

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 25.12.0
Description LibreNMS, an auto-discovering PHP/MySQL/SNMP based network monitoring tool, contains a stored cross-site scripting issue in the Alert Rule API. The alert rule name is not properly sanitized, allowing injection of HTML code when creating or updating alert rules via the LibreNMS API. The vulnerable API endpoint is used for creating and updating alert rules. The alert rule name is the vulnerable parameter.
Recommendations Update to version 25.12.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68614
GHSA-C89F-8G7G-59WJ
ZDI-25-1182

Affected Products

Librenms