#VU127453 Cross-site scripting in LibreNMS - CVE-2024-51496
Published: November 15, 2024 / Updated: April 24, 2026
LibreNMS
LibreNMS Project
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in a user's session.
The vulnerability exists due to cross-site scripting in the "metric" parameter of the /wireless and /health endpoints when handling requests containing a crafted metric parameter. A remote privileged user can send a specially crafted URL to execute arbitrary JavaScript in a user's session.
User interaction is required to access the crafted page.