Stored XSS in LibreNMS Network Monitoring System
CVE-2025-23199

5.4MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
16 January 2025

What is CVE-2025-23199?

LibreNMS, a popular community-based network monitoring solution, has a vulnerability that allows remote attackers to perform stored XSS attacks via a specific parameter in the AJAX form. If the affected version (up to 24.10.1) is used, attackers can inject malicious scripts that execute when users interact with compromised data on the platform. This could lead to unauthorized actions and potential data exposure for users. Users are highly encouraged to upgrade to version 24.11.0, which addresses this vulnerability. There are currently no known workarounds to mitigate the issue.

Affected Version(s)

librenms < 24.11.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.