Reflected Cross-Site Scripting Vulnerability in LibreNMS Network Monitoring Tool
CVE-2025-65013
6.2MEDIUM
What is CVE-2025-65013?
LibreNMS, a popular network monitoring tool that utilizes PHP, MySQL, and SNMP, has been found to contain a reflected cross-site scripting vulnerability. This issue lives within the /maps/nodeimage endpoint, where the Image Name parameter is reflected in the application’s HTTP response without appropriate output encoding or sanitization. As a result, malicious actors can design a URL that executes arbitrary JavaScript in the browser of a targeted user when accessed. This vulnerability has been remedied in version 25.11.0 of LibreNMS.
Affected Version(s)
librenms < 25.11.0
