CVE-2024-32479

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://github.com/librenms/librenms/blob/a61c11db7e8ef6a437ab55741658be2be7d14d34/app/Http/Controllers/ServiceTemplateController.php#L67C23-L67C23 - () https://github.com/librenms/librenms/blob/a61c11db7e8ef6a437ab55741658be2be7d14d34/app/Http/Controllers/ServiceTemplateController.php#L67C23-L67C23 -
References () https://github.com/librenms/librenms/commit/19344f0584d4d6d4526fdf331adc60530e3f685b - () https://github.com/librenms/librenms/commit/19344f0584d4d6d4526fdf331adc60530e3f685b -
References () https://github.com/librenms/librenms/security/advisories/GHSA-72m9-7c8x-pmmw - () https://github.com/librenms/librenms/security/advisories/GHSA-72m9-7c8x-pmmw -

23 Apr 2024, 12:52

Type Values Removed Values Added
Summary
  • (es) LibreNMS es un sistema de monitoreo de red de código abierto basado en PHP/MySQL/SNMP. Antes de la versión 24.4.0, había una sanitización inadecuada en el nombre de la plantilla "Servicio", lo que puede provocar que se almacenen Cross Site Scripting. La versión 24.4.0 corrige esta vulnerabilidad.

22 Apr 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-22 22:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-32479

Mitre link : CVE-2024-32479

CVE.ORG link : CVE-2024-32479


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')