Описание
Cross-site Scripting in LibreNMS
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
Пакеты
Наименование
librenms/librenms
composer
Затронутые версииВерсия исправления
< 21.3.0
21.3.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 4 лет назад
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.