CVE-2024-49754 Information

Description

LibreNMS is an open-source PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the oken\ parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users’ sessions compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.

Reference

https://github.com/librenms/librenms/security/advisories/GHSA-gfwr-xqmj-j27v https://github.com/librenms/librenms/commit/25988a937cbaebd2ba4c0517510206c404dfb359

Share on: