CVE-2024-49759 Information
Nov 16, 2024
cve
Description
LibreNMS is an open-source PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the \Manage User Access\ page allows authenticated users to inject arbitrary JavaScript through the ill_name\ parameter when creating a new bill. This vulnerability can lead to the execution of malicious code when visiting the \Bill Access\ dropdown in the user’s \Manage Access\ page potentially compromising user sessions and allowing unauthorized actions. This vulnerability is fixed in 24.10.0.
Reference
https://github.com/librenms/librenms/security/advisories/GHSA-888j-pjqh-fx58 https://github.com/librenms/librenms/commit/237f4d2e818170171dfad6efad36a275cd2ba8d0
Share on: