CVE-2024-47526

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh.
Configurations

No configuration.

History

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) LibreNMS es un sistema de monitoreo de red de código abierto basado en PHP/MySQL/SNMP. Una vulnerabilidad de tipo Self Cross-Site Scripting (Self-XSS) en la función "Alert Templates" permite a los usuarios inyectar código JavaScript arbitrario en el nombre de la plantilla de alerta. Este script se ejecuta inmediatamente después de enviarlo, pero no persiste después de actualizar la página.

01 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 21:15

Updated : 2024-10-04 13:50


NVD link : CVE-2024-47526

Mitre link : CVE-2024-47526

CVE.ORG link : CVE-2024-47526


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')