Stored XSS Vulnerability in LibreNMS Network Monitoring System
CVE-2025-23200
What is CVE-2025-23200?
LibreNMS, a community-driven network monitoring system, has a vulnerability that affects versions up to 24.10.1, which can be exploited through a stored XSS attack via the ajax_form.php parameter: state. This vulnerability allows remote attackers to inject malicious scripts that execute when users interact with the page showing the injected data. As a result, potential unauthorized actions or data exposure can occur, compromising user security and integrity. It is crucial for users to upgrade to version 24.11.0 to mitigate this risk effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
librenms < 24.11.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
