Stored Cross-Site Scripting in LibreNMS Network Monitoring System
CVE-2024-49759

5.4MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
15 November 2024

What is CVE-2024-49759?

A Stored Cross-Site Scripting vulnerability affects the Manage User Access page in LibreNMS, a popular open-source network monitoring system. This flaw allows authenticated users to inject arbitrary JavaScript via the bill_name parameter while creating a new bill. When a user accesses the 'Bill Access' dropdown in the Manage Access section, the injected script may execute, potentially compromising user sessions and enabling unauthorized actions. To mitigate this issue, users should upgrade to LibreNMS version 24.10.0 or later.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.