LibreNMS
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*
- <= 25.6.0
A reflected cross-site scripting vulnerability has been identified in LibreNMS versions prior to 25.7.0. The issue arises in the report_this function within the includes/functions.php file, where improper filtering allows the project_issues parameter to execute malicious scripts. This vulnerability has been patched in version 25.7.0.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, send a GET request with the project_issues parameter set to a JavaScript URL, such as 'javascript:alert(document.cookie)'. This will trigger the cross-site scripting vulnerability by executing the injected script in the user's browser.
Users can upgrade to LibreNMS version 25.7.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.