LibreNMS
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*
- 25.4.0
A stored cross-site scripting vulnerability has been identified in LibreNMS versions through 25.4.0. The issue resides in the 'group name' parameter of the 'http://localhost/poller/groups' form. This vulnerability allows attackers to inject malicious scripts that are executed when other users view the affected page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
To reproduce this vulnerability, first enable the 'distributed_poller' setting. Then, create a new poller group and inject a script payload into the 'group name' parameter. After the group is saved, navigate to the 'http://localhost/addhost' page to observe the execution of the injected script.
Users can upgrade to LibreNMS version 25.5.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.