LibreNMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in LibreNMS versions prior to 24.10.1. The issue resides in the 'Description' parameter of the '/ajax_form.php' endpoint, allowing remote attackers to inject malicious scripts. When the injected script is viewed or interacted with, it executes immediately, potentially leading to unauthorized actions or data exposure. This vulnerability has been patched in LibreNMS version 24.11.0.

Impact

Exploitation of this vulnerability allows for the execution of injected scripts, potentially leading to unauthorized actions or data exposure.

Reproduction

To reproduce this vulnerability, add a new device through the LibreNMS interface. After the device is created, edit it and navigate to the 'ports' section. In the 'Description' field, enter a payload that includes a script injection, such as an image tag with an 'onerror' event. Save the changes, and the injected script will execute when accessing the 'ports' tab or hovering over the modified 'Port' field value.

Remediation

Users are advised to upgrade to LibreNMS version 24.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.7
exploitability
6.3
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.