CVE-2024-51496

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malicious code when a user accesses the page with a malicious "metric" parameter, potentially compromising their session and allowing unauthorized actions. This vulnerability is fixed in 24.10.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 23:33

Type Values Removed Values Added
CPE cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
First Time Librenms librenms
Librenms
References () https://github.com/librenms/librenms/commit/aef739a438ffb507e927a4ec87b359164a7a053a - () https://github.com/librenms/librenms/commit/aef739a438ffb507e927a4ec87b359164a7a053a - Patch
References () https://github.com/librenms/librenms/security/advisories/GHSA-28p7-f6h6-3jh3 - () https://github.com/librenms/librenms/security/advisories/GHSA-28p7-f6h6-3jh3 - Exploit, Vendor Advisory

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) LibreNMS es un sistema de monitoreo de red de código abierto basado en PHP/MySQL/SNMP. Una vulnerabilidad de tipo cross site scripting (XSS) reflejado en el parámetro "metric" de los endpoints "/wireless" y "/health" permite a los atacantes inyectar código JavaScript arbitrario. Esta vulnerabilidad da como resultado la ejecución de código malicioso cuando un usuario accede a la página con un parámetro "metric" malicioso, lo que potencialmente compromete su sesión y permite acciones no autorizadas. Esta vulnerabilidad se corrigió en 24.10.0.

15 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 16:15

Updated : 2024-11-21 23:33


NVD link : CVE-2024-51496

Mitre link : CVE-2024-51496

CVE.ORG link : CVE-2024-51496


JSON object : View

Products Affected

librenms

  • librenms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')