HTTP: LibreNMS Device Overview Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against LibreNMS . It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users' sessions, compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.

Affected Products

Librenms librenms

References

CVE: CVE-2024-49754

Short Name
HTTP:XSS:LIBRE-NMS-DVCE-OVRVIEW
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-49754 CVE-2024-50352 CVE-2024-53457 Cross-Site Device LibreNMS Overview Scripting Stored
Release Date
12/26/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3785
False Positive
Unknown
Vendors

Librenms

Found a potential security threat?