Cross-site Scripting (XSS) - Reflected in librenms/librenms
CVE-2023-4347

7.6HIGH

Key Information:

Vendor

Librenms

Vendor
CVE Published:
15 August 2023

What is CVE-2023-4347?

A reflected Cross-site Scripting (XSS) vulnerability was identified in LibreNMS prior to version 23.8.0. This vulnerability allows an unauthorized attacker to inject malicious scripts into web pages viewed by other users. If successfully executed, this could lead to potential information theft or the execution of arbitrary actions on behalf of unsuspecting users, putting sensitive data at risk. Users are advised to upgrade their installations to the latest version to mitigate this security risk.

Affected Version(s)

librenms/librenms < 23.8.0

References

EPSS Score

82% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.