Overview
- Description
- LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "logs" tab of a device allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malicious code when a user accesses the page with a malicious "section" parameter, potentially compromising their session and enabling unauthorized actions. The issue arises from a lack of sanitization in the "report_this()" function. This vulnerability is fixed in 24.10.0.
- Source
- security-advisories@github.com
- NVD status
- Received
Risk scores
CVSS 3.1
- Type
- Secondary
- Base score
- 4.8
- Impact score
- 2.7
- Exploitability score
- 1.7
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Weaknesses
- security-advisories@github.com
- CWE-79
Social media
- Hype score
- Not currently trending
CVE-2024-50351 Reflected XSS Vulnerability in LibreNMS Logs Fixed in 24.10.0 LibreNMS is a free network monitoring tool using PHP, MySQL, and SNMP. There is a Reflected Cross-Site Scripting (XSS) vulnerability in... https://t.co/hdSNtAn2my
@VulmonFeeds
15 Nov 2024
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-50351 LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "lo… https://t.co/3t67vJmQWw
@CVEnew
15 Nov 2024
226 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes