LibreNMS Cross-Site Scripting Vulnerability in Community Parameter on Add Host Page

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in LibreNMS versions through 24.10.1. The issue arises on the '/addhost' page, specifically within the community parameter, allowing remote attackers to inject malicious scripts. These scripts execute immediately when a user interacts with the page, potentially leading to unauthorized actions or data exposure. The vulnerability has been patched in version 24.11.0.

Impact

Exploitation of this vulnerability allows for the execution of injected scripts, which could lead to unauthorized actions or exposure of sensitive data.

Reproduction

To reproduce this vulnerability, navigate to the '/addhost' page and fill in the required fields. In the Community field, enter a payload that includes a script injection, such as an image tag with an error event handler. After submitting the form, the injected script will execute when an error alert related to the community response appears.

Remediation

Users are advised to upgrade to LibreNMS version 24.11.0 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.7
exploitability
7.7
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.