Stored Cross-Site Scripting in LibreNMS Network Monitoring System
CVE-2024-49759
5.4MEDIUM
What is CVE-2024-49759?
A Stored Cross-Site Scripting vulnerability affects the Manage User Access page in LibreNMS, a popular open-source network monitoring system. This flaw allows authenticated users to inject arbitrary JavaScript via the bill_name parameter while creating a new bill. When a user accesses the 'Bill Access' dropdown in the Manage Access section, the injected script may execute, potentially compromising user sessions and enabling unauthorized actions. To mitigate this issue, users should upgrade to LibreNMS version 24.10.0 or later.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published