
We found results for “”
CVE-2024-47526
Good to know:

Date: October 1, 2024
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh.
Language: PHP
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version librenms/librenms - dev-laf-patch-1;librenms/librenms - dev-revert-16462-truenas-scale-(new-os);librenms/librenms - dev-php81;librenms/librenms - dev-laf-patch-2;librenms/librenms - dev-dependabot/npm_and_yarn/vue-3.0.0;librenms/librenms - dev-translation-update;librenms/librenms - dev-dependabot/npm_and_yarn/nanoid-3.3.8;librenms/librenms - dev-dependabot/npm_and_yarn/elliptic-6.6.0;librenms/librenms - no_fix;librenms/librenms - dev-dependabot/composer/laravel/framework-10.48.23;librenms/librenms - dev-Fix-for-Aruba-switches-alerting-on-Stack-Topology;librenms/librenms - dev-dependabot/composer/tecnickcom/tcpdf-6.8.0;librenms/librenms - dev-dependabot/composer/symfony/http-client-6.4.14;librenms/librenms - dev-huawei-vrp-vlan-quirks;librenms/librenms - 24.9.0;librenms/librenms - dev-cisco_trans;librenms/librenms - dev-vlan-discovery-only;librenms/librenms - dev-docs-edit-link;librenms/librenms - dev-revert-16731-sensor_graphs;librenms/librenms - dev-dependabot/composer/league/commonmark-2.6.0;librenms/librenms - dev-dependabot/composer/nesbot/carbon-2.72.6
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |