Stored Cross-Site Scripting Vulnerability in LibreNMS Network Monitoring Software
CVE-2024-50350
What is CVE-2024-50350?
LibreNMS, a widely used open-source network monitoring system, has a stored cross-site scripting vulnerability in its 'Port Settings' page. This issue arises when authenticated users can inject arbitrary JavaScript through the 'name' parameter during the creation of a new Port Group. If an affected Port Group is added to a device, the execution of malicious code occurs when users visit the 'Port Settings' page, posing significant risks to user sessions and enabling unauthorized actions. Users are urged to upgrade to version 24.10.0 or later to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
