Stored Cross-Site Scripting in LibreNMS API Access for Authenticated Users
CVE-2024-49754
5.4MEDIUM
What is CVE-2024-49754?
LibreNMS, an open-source network monitoring system, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability within its API Access page. Authenticated users can exploit this vulnerability by injecting arbitrary JavaScript code through the 'token' parameter when creating new API tokens. This jeopardizes the security of other users' sessions, facilitating unauthorized actions. To mitigate this flaw, users are advised to upgrade to version 24.10.0, where the issue has been resolved.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published