LibreNMS
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*
- <= 25.12.0
A reflected cross-site scripting (XSS) vulnerability has been identified in LibreNMS versions through 25.12.0. The issue arises in the email input field, where malicious scripts can be injected and executed. This vulnerability has been addressed in version 26.2.0.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, navigate to the email settings page. In the email address input field, enter a payload that includes a script, such as an image tag with an 'onerror' event. This will trigger an alert displaying the document's cookies, demonstrating the successful execution of the injected script.
Users can upgrade to LibreNMS version 26.2.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.