Cross-site Scripting (XSS) - Stored in librenms/librenms
CVE-2023-4982

9.8CRITICAL

Key Information:

Vendor

Librenms

Vendor
CVE Published:
15 September 2023

What is CVE-2023-4982?

A stored cross-site scripting (XSS) vulnerability exists in LibreNMS prior to version 23.9.0. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising user information and session cookies. The vulnerability has been documented in the GitHub repository, highlighting the importance of updating to the latest version to mitigate the risk.

Affected Version(s)

librenms/librenms < 23.9.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.