icon

We found results for “

CVE-2024-47526

Good to know:

icon

Date: October 1, 2024

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version librenms/librenms - dev-laf-patch-1;librenms/librenms - dev-revert-16462-truenas-scale-(new-os);librenms/librenms - dev-php81;librenms/librenms - dev-laf-patch-2;librenms/librenms - dev-dependabot/npm_and_yarn/vue-3.0.0;librenms/librenms - dev-translation-update;librenms/librenms - dev-dependabot/npm_and_yarn/nanoid-3.3.8;librenms/librenms - dev-dependabot/npm_and_yarn/elliptic-6.6.0;librenms/librenms - no_fix;librenms/librenms - dev-dependabot/composer/laravel/framework-10.48.23;librenms/librenms - dev-Fix-for-Aruba-switches-alerting-on-Stack-Topology;librenms/librenms - dev-dependabot/composer/tecnickcom/tcpdf-6.8.0;librenms/librenms - dev-dependabot/composer/symfony/http-client-6.4.14;librenms/librenms - dev-huawei-vrp-vlan-quirks;librenms/librenms - 24.9.0;librenms/librenms - dev-cisco_trans;librenms/librenms - dev-vlan-discovery-only;librenms/librenms - dev-docs-edit-link;librenms/librenms - dev-revert-16731-sensor_graphs;librenms/librenms - dev-dependabot/composer/league/commonmark-2.6.0;librenms/librenms - dev-dependabot/composer/nesbot/carbon-2.72.6

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us