Cross-site scripting in LibreNMS - CVE-2024-47525

 

Cross-site scripting in LibreNMS - CVE-2024-47525

Published: October 1, 2024 / Updated: May 5, 2026


Vulnerability identifier: #VU129739
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-47525
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the context of other users' sessions.

The vulnerability exists due to cross-site scripting in print-alert-rules.php when creating an alert rule with crafted input in the Title field. A remote privileged user can submit a specially crafted Title value to execute arbitrary JavaScript in the context of other users' sessions.

User interaction is required when another user loads the affected page.


Affected software

LibreNMS

How to mitigate CVE-2024-47525

Install security update from vendor's website.

LibreNMS - update to 24.9.0

External References

Related Security Bulletins