Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8phr-637g-pxrg

Опубликовано: 17 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

LibreNMS Cross-site Scripting at Device groups Deletion feature

Summary

XSS attacks occurs when application is not sanitising inputs properly and rendering the code from user input to browser which could allow an attacker to execute malicious javascript code.

PoC

  1. Login
  2. Create a device group in /device-groups
  3. Name it as "><img src=x onerror=alert(1);>
  4. save it
  5. Go to services and create a service template and add that device group into that and save it
  6. After that go back to device groups and delete that device, you will see XSS payload popup in message Screenshot 2023-11-08 at 9 15 56 PM

Vulnerable code:

https://github.com/librenms/librenms/blob/63eeeb71722237d1461a37bb6da99fda25e02c91/app/Http/Controllers/DeviceGroupController.php#L173C21-L173C21

Line 173 is not sanitizing device name properly Screenshot 2023-11-08 at 9 26 14 PM

Impact

Cross site scripting can lead to cookie stealing attacks

Пакеты

Наименование

librenms/librenms

composer
Затронутые версииВерсия исправления

< 23.11.0

23.11.0

EPSS

Процентиль: 52%
0.00295
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 лет назад

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been addressed in commit `faf66035ea` which has been included in release version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 52%
0.00295
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79