Cross-site scripting in LibreNMS - CVE-2024-51494

 

Cross-site scripting in LibreNMS - CVE-2024-51494

Published: November 15, 2024 / Updated: May 5, 2026


Vulnerability identifier: #VU129728
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-51494
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the context of other users' sessions.

The vulnerability exists due to cross-site scripting in the Port Settings page in librenms/app/Http/Controllers/Table/EditPortsController.php when rendering the user-supplied "descr" parameter while editing a device's port settings. A remote privileged user can submit a specially crafted descr value to execute arbitrary JavaScript in the context of other users' sessions.

User interaction is required when the "Port Settings" page is visited.


Affected software

LibreNMS

How to mitigate CVE-2024-51494

Install security update from vendor's website.

LibreNMS - update to 24.10.0

External References

Related Security Bulletins