#VU127449 Cross-site scripting in LibreNMS - CVE-2025-23200
Published: January 16, 2025 / Updated: April 24, 2026
LibreNMS
LibreNMS Project
Description
The vulnerability allows a remote user to inject malicious scripts.
The vulnerability exists due to improper neutralization of input during web page generation in the dynamic_override_config function in functions.inc.php and the misc section page when processing the state parameter in ajax_form.php. A remote user can submit a specially crafted state value to inject malicious scripts.
User interaction is required when a user views or interacts with the page displaying the stored data.