Логотип exploitDog
bind:CVE-2024-52526
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52526

Количество 2

Количество 2

nvd логотип

CVE-2024-52526

около 1 года назад

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-8fh4-942r-jf2g

около 1 года назад

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-52526

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.

CVSS3: 4.8
1%
Низкий
около 1 года назад
github логотип
GHSA-8fh4-942r-jf2g

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php

CVSS3: 7.5
1%
Низкий
около 1 года назад

Уязвимостей на страницу