Librenms

Librenms

105 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 15.11.2024 16:15:34
  • Zuletzt bearbeitet 20.11.2024 14:40:36

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the application did not properly sanitize the user input, when the ExamplePlugin enable, if java script code is inside the dev...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 01.10.2024 21:15:08
  • Zuletzt bearbeitet 19.12.2024 21:15:08

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the ...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 01.10.2024 21:15:07
  • Zuletzt bearbeitet 07.10.2024 19:07:30

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary JavaScript through the "Details" section (w...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 01.10.2024 21:15:07
  • Zuletzt bearbeitet 19.12.2024 15:43:50

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user input in the Device Groups name, when user see the detail of the Device Gr...

Exploit
  • EPSS 26.24%
  • Veröffentlicht 01.10.2024 21:15:07
  • Zuletzt bearbeitet 07.10.2024 19:08:18

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulne...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 01.10.2024 21:15:07
  • Zuletzt bearbeitet 19.12.2024 15:49:50

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script ...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 01.10.2024 21:15:07
  • Zuletzt bearbeitet 07.10.2024 19:08:41

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary JavaScript through the device name ("hos...

Exploit
  • EPSS 20.28%
  • Veröffentlicht 22.04.2024 23:15:50
  • Zuletzt bearbeitet 02.01.2025 21:38:11

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporat...

Exploit
  • EPSS 34.13%
  • Veröffentlicht 22.04.2024 22:15:08
  • Zuletzt bearbeitet 02.01.2025 21:32:19

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability...

Exploit
  • EPSS 19.11%
  • Veröffentlicht 22.04.2024 22:15:07
  • Zuletzt bearbeitet 02.01.2025 21:29:53

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the pa...