CVE-2023-48295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/11/2023
Last modified:
25/11/2023

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been addressed in commit `faf66035ea` which has been included in release version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* 23.11.0 (excluding)