librenms
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*
- <= 24.10.1
A cross-site scripting (XSS) vulnerability has been identified in LibreNMS versions through 24.10.1. The issue arises on the '/addhost' page, specifically within the community parameter, allowing remote attackers to inject malicious scripts. These scripts execute immediately when a user interacts with the page, potentially leading to unauthorized actions or data exposure. The vulnerability has been patched in version 24.11.0.
Exploitation of this vulnerability allows for the execution of injected scripts, which could lead to unauthorized actions or exposure of sensitive data.
To reproduce this vulnerability, navigate to the '/addhost' page and fill in the required fields. In the Community field, enter a payload that includes a script injection, such as an image tag with an error event handler. After submitting the form, the injected script will execute when an error alert related to the community response appears.
Users are advised to upgrade to LibreNMS version 24.11.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.