icon

We found results for “

CVE-2024-47528

Good to know:

icon

Date: October 1, 2024

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the upload of SVG file that can contain XSS payload which will trigger on load. This led to Stored Cross-Site Scripting (XSS). The vulnerability is fixed in 24.9.0.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Improper Encoding or Escaping of Output

CWE-116

Unrestricted Upload of File with Dangerous Type

CWE-434

Top Fix

icon

Upgrade Version

Upgrade to version librenms/librenms - no_fix;librenms/librenms - dev-dependabot/composer/nesbot/carbon-2.72.6;librenms/librenms - dev-laf-patch-1;librenms/librenms - dev-dependabot/npm_and_yarn/vue-3.0.0;librenms/librenms - dev-docs-edit-link;librenms/librenms - dev-vlan-discovery-only;librenms/librenms - dev-huawei-vrp-vlan-quirks;librenms/librenms - dev-dependabot/composer/tecnickcom/tcpdf-6.8.0;librenms/librenms - dev-revert-16731-sensor_graphs;librenms/librenms - dev-Fix-for-Aruba-switches-alerting-on-Stack-Topology;librenms/librenms - dev-revert-16462-truenas-scale-(new-os);librenms/librenms - dev-laf-patch-2;librenms/librenms - dev-dependabot/composer/laravel/framework-10.48.23;librenms/librenms - dev-dependabot/npm_and_yarn/elliptic-6.6.0;librenms/librenms - dev-translation-update;librenms/librenms - dev-dependabot/composer/league/commonmark-2.6.0;librenms/librenms - dev-dependabot/npm_and_yarn/nanoid-3.3.8;librenms/librenms - dev-cisco_trans;librenms/librenms - dev-dependabot/composer/symfony/http-client-6.4.14;librenms/librenms - 24.9.0;librenms/librenms - dev-php81

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us