CVE-2024-51494

MEDIUM

Librenms < 24.10.0 - XSS

Title source: rule
STIX 2.1

Description

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port settings. This vulnerability can lead to the execution of malicious code when the "Port Settings" page is visited, potentially compromising the user's session and allowing unauthorized actions. This vulnerability is fixed in 24.10.0.

Scores

CVSS v3 4.8
EPSS 0.0086
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
librenms/librenms < 24.10.0
librenms/librenms 0 - 24.10.0Packagist
Published Nov 15, 2024
Tracked Since Feb 18, 2026