CVE-2024-49754 Information
Nov 16, 2024
cve
Description
LibreNMS is an open-source PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the oken\ parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users’ sessions compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.
Reference
https://github.com/librenms/librenms/security/advisories/GHSA-gfwr-xqmj-j27v https://github.com/librenms/librenms/commit/25988a937cbaebd2ba4c0517510206c404dfb359
Share on: