#VU127452 Cross-site scripting in LibreNMS - CVE-2024-50351
Published: November 15, 2024 / Updated: April 24, 2026
LibreNMS
LibreNMS Project
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in the context of a user's session.
The vulnerability exists due to improper neutralization of input during web page generation in the report_this() function and the device logs tab when handling the section parameter. A remote privileged user can send a specially crafted URL to execute arbitrary JavaScript in the context of a user's session.
User interaction is required to access the crafted page.