CVE-2024-47526

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Oct 1, 2024
Updated: Dec 19, 2024
CWE ID 79

Summary

CVE-2024-47526 is a newly disclosed vulnerability affecting LibreNMS, an open-source network monitoring system. The issue involves a Self Cross-Site Scripting (Self-XSS) flaw in the "Alert Templates" feature. This vulnerability allows users to inject malicious JavaScript code into the alert template name. Once submitted, the script runs immediately but does not persist after a page refresh. Despite not being permanently stored, this security weakness could still result in unintended site behavior or data exposure for affected users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share