CVE-2024-49754
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 15, 2024
CWE ID 79
Summary
CVE-2024-49754 is a stored Cross-Site Scripting (XSS) vulnerability affecting LibreNMS, an open-source network monitoring system. The flaw lies in the API-Access page, where authenticated users can inject malicious JavaScript code through the "token" parameter when creating a new API token. This issue can lead to the execution of malicious scripts in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions. This vulnerability has been resolved in LibreNMS version 24.10.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibreNMS
Affected Vendors
- LibreNMS