Cross-site scripting in LibreNMS - CVE-2025-23199

 

Cross-site scripting in LibreNMS - CVE-2025-23199

Published: January 16, 2025 / Updated: April 24, 2026


Vulnerability identifier: #VU127448
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-23199
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject malicious scripts.

The vulnerability exists due to improper neutralization of input during web page generation in the /ajax_form.php endpoint and port description rendering logic when handling the descr parameter in update-ifalias requests and later displaying the stored value. A remote user can submit a specially crafted description value to inject malicious scripts.

User interaction is required when the stored data is viewed or interacted with, including accessing the ports tab or hovering over the modified port field.


Affected software

LibreNMS

How to mitigate CVE-2025-23199

Install security update from vendor's website.

LibreNMS - update to 24.11.0

External References

Related Security Bulletins