Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3047 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh. |
Github GHSA |
GHSA-gcgp-q2jq-fw52 | LibreNMS has Stored Cross-site Scripting vulnerability in "Alert Templates" feature |
Wed, 02 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librenms
Librenms librenms |
|
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh. | |
| Title | LibreNMS has a Self-XSS ('Cross-site Scripting') in librenms/includes/html/modal/alert_template.inc.php | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-02T13:03:02.417Z
Reserved: 2024-09-25T21:46:10.928Z
Link: CVE-2024-47526
Updated: 2024-10-02T13:02:58.851Z
Status : Analyzed
Published: 2024-10-01T21:15:07.740
Modified: 2024-12-19T15:49:50.127
Link: CVE-2024-47526
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA