
We found results for “”
CVE-2024-47528
Good to know:

Date: October 1, 2024
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the upload of SVG file that can contain XSS payload which will trigger on load. This led to Stored Cross-Site Scripting (XSS). The vulnerability is fixed in 24.9.0.
Language: PHP
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Top Fix

Upgrade Version
Upgrade to version librenms/librenms - no_fix;librenms/librenms - dev-dependabot/composer/nesbot/carbon-2.72.6;librenms/librenms - dev-laf-patch-1;librenms/librenms - dev-dependabot/npm_and_yarn/vue-3.0.0;librenms/librenms - dev-docs-edit-link;librenms/librenms - dev-vlan-discovery-only;librenms/librenms - dev-huawei-vrp-vlan-quirks;librenms/librenms - dev-dependabot/composer/tecnickcom/tcpdf-6.8.0;librenms/librenms - dev-revert-16731-sensor_graphs;librenms/librenms - dev-Fix-for-Aruba-switches-alerting-on-Stack-Topology;librenms/librenms - dev-revert-16462-truenas-scale-(new-os);librenms/librenms - dev-laf-patch-2;librenms/librenms - dev-dependabot/composer/laravel/framework-10.48.23;librenms/librenms - dev-dependabot/npm_and_yarn/elliptic-6.6.0;librenms/librenms - dev-translation-update;librenms/librenms - dev-dependabot/composer/league/commonmark-2.6.0;librenms/librenms - dev-dependabot/npm_and_yarn/nanoid-3.3.8;librenms/librenms - dev-cisco_trans;librenms/librenms - dev-dependabot/composer/symfony/http-client-6.4.14;librenms/librenms - 24.9.0;librenms/librenms - dev-php81
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |