CVE-2024-50352
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-50352 is a newly disclosed stored Cross-Site Scripting (XSS) vulnerability affecting LibreNMS, an open-source network monitoring system. The flaw resides in the "Services" section of the Device Overview page, where users can add services to devices using a maliciously crafted "name" parameter. This input allows the injection of arbitrary JavaScript code, which could be executed in the context of other users' sessions. The consequences of this vulnerability can range from compromised user accounts to unauthorized actions. It is recommended that users upgrade to LibreNMS version 24.10.0 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibreNMS
Affected Vendors
- LibreNMS