CVE-2025-23200
- EPSS 4.29%
- Veröffentlicht 16.01.2025 23:15:08
- Zuletzt bearbeitet 25.03.2025 15:12:30
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts....
CVE-2025-23201
- EPSS 0.03%
- Veröffentlicht 16.01.2025 23:15:08
- Zuletzt bearbeitet 25.03.2025 14:57:12
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malic...
CVE-2024-56144
- EPSS 0.11%
- Veröffentlicht 16.01.2025 23:15:07
- Zuletzt bearbeitet 28.04.2025 16:44:52
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versi...
CVE-2024-53457
- EPSS 32.87%
- Veröffentlicht 05.12.2024 22:15:20
- Zuletzt bearbeitet 07.04.2025 14:55:43
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
CVE-2024-52526
- EPSS 0.88%
- Veröffentlicht 15.11.2024 16:15:38
- Zuletzt bearbeitet 20.11.2024 14:39:19
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" param...
CVE-2024-51494
- EPSS 0.64%
- Veröffentlicht 15.11.2024 16:15:37
- Zuletzt bearbeitet 20.11.2024 14:40:56
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when edi...
CVE-2024-51495
- EPSS 0.67%
- Veröffentlicht 15.11.2024 16:15:37
- Zuletzt bearbeitet 20.11.2024 14:41:07
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter w...
CVE-2024-51496
- EPSS 0.84%
- Veröffentlicht 15.11.2024 16:15:37
- Zuletzt bearbeitet 21.11.2024 23:33:42
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. Thi...
CVE-2024-51497
- EPSS 0.67%
- Veröffentlicht 15.11.2024 16:15:37
- Zuletzt bearbeitet 20.11.2024 14:41:19
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject arbitrary JavaScript through the "unit" parameter w...
CVE-2024-50355
- EPSS 0.07%
- Veröffentlicht 15.11.2024 16:15:36
- Zuletzt bearbeitet 20.11.2024 14:39:36
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside...