librenms
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*
- 24.10.1
A stored cross-site scripting vulnerability has been identified in LibreNMS versions prior to 24.10.1. The issue resides in the 'ajax_form.php' file, specifically within the 'state' parameter. This vulnerability allows remote attackers to inject malicious scripts, which are executed immediately when a user interacts with the affected page. The injection occurs because untrusted data is retrieved and displayed without proper sanitization, potentially leading to unauthorized actions or exposure of sensitive information.
Exploitation of this vulnerability allows for the execution of injected scripts in the context of the user viewing the affected page, which could lead to unauthorized actions or data exposure.
To reproduce this vulnerability, add a new device through the LibreNMS interface. Then, edit the device and navigate to the 'Misc' section. In one of the available fields, such as 'Override default ssh port' or 'Unix agent port', enter a payload that includes an image tag with an 'onerror' attribute. After saving the changes, the injected script will execute when the page is loaded, demonstrating the cross-site scripting vulnerability.
Users are advised to upgrade to LibreNMS version 24.11.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.