Tony Murray
50 exploits
Active since Jul 2020
librenms < 23.9.0 - Code Injection
CVSS 5.4
librenms < 23.9.0 - DOM-Based Cross-Site Scripting
CVSS 6.1
librenms < 23.9.0 - Reflected Cross-Site Scripting
CVSS 5.4
librenms < 23.9.0 - Cross-Site Scripting
CVSS 5.4
librenms < 23.9.0 - DOM-Based Cross-Site Scripting
CVSS 5.4
librenms < 23.9.0 - Stored Cross-Site Scripting
CVSS 5.4
GitHub librenms/librenms <23.9.1 - XSS
CVSS 6.1
librenms/librenms < 23.10.0 - SQL Injection
CVSS 6.5
LibreNMS < 24.4.0 - Authenticated SQL Injection via Search Package Parameter
CVSS 7.1
LibreNMS < 24.4.0 - Stored Cross-Site Scripting via Service Template Name
CVSS 7.1
LibreNMS < 24.9.0 - Authenticated Stored Cross-Site Scripting in Alert Transports Details Section
CVSS 7.5
LibreNMS < 24.9.0 - Stored Cross-Site Scripting in Device Group Name
CVSS 7.2
LibreNMS < 24.9.0 - Authenticated Stored Cross-Site Scripting via Alert Rules Title Field
CVSS 7.5
LibreNMS < 24.9.0 - Authenticated Stored Cross-Site Scripting via Device Name Hostname Parameter
CVSS 7.5
LibreNMS < 24.9.0 - Stored Cross-Site Scripting via Custom Map Background SVG Upload
CVSS 4.8
LibreNMS < 24.10.0 - Authenticated Stored Cross-Site Scripting via Device Notes
CVSS 4.8
LibreNMS < 24.10.0 - Reflected Cross-Site Scripting via Device Logs Section Parameter
CVSS 4.8
LibreNMS < 24.10.0 - Authenticated Stored Cross-Site Scripting via Device Display Name
CVSS 4.8
LibreNMS < 24.10.0 - Authenticated Stored Cross-Site Scripting via Custom OID Unit Parameter
CVSS 4.8
LibreNMS < 24.10.0 - Authenticated Stored Cross-Site Scripting via Service Descr Parameter
CVSS 4.8
LibreNMS < 25.7.0 - Remote File Inclusion via ajax_form.php Type Parameter
CVSS 7.5
LibreNMS < 25.8.0 - Stored Cross-Site Scripting in Alert Template Creation
CVSS 5.5
LibreNMS < 25.7.0 - Reflected Cross-Site Scripting via report_this Function
CVSS 6.1
LibreNMS <= 25.8.0 - Stored Cross-Site Scripting in Alert Transports Management
CVSS 5.5
LibreNMS < 25.10.0 - Stored Cross-Site Scripting in Alert Rule Name
CVSS 3.8