Stored XSS in LibreNMS Network Monitoring System
CVE-2025-23199
5.4MEDIUM
What is CVE-2025-23199?
LibreNMS, a popular community-based network monitoring solution, has a vulnerability that allows remote attackers to perform stored XSS attacks via a specific parameter in the AJAX form. If the affected version (up to 24.10.1) is used, attackers can inject malicious scripts that execute when users interact with compromised data on the platform. This could lead to unauthorized actions and potential data exposure for users. Users are highly encouraged to upgrade to version 24.11.0, which addresses this vulnerability. There are currently no known workarounds to mitigate the issue.
Affected Version(s)
librenms < 24.11.0