CVE-2024-49758 Information

Description

LibreNMS is an open-source PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device the application did not properly sanitize the user input when the ExamplePlugin enable if java script code is inside the device’s Notes its will be trigger. This vulnerability is fixed in 24.10.0.

Reference

https://github.com/librenms/librenms/security/advisories/GHSA-c86q-rj37-8f85 https://github.com/librenms/librenms/commit/24b142d753898e273ec20b542a27dd6eb530c7d8

Share on: