← Back to browse · API

CVE-2024-49754

Severity
HIGH
CVSS
7.5
EPSS
0.69818
Risk score
54.44
CISA KEV
No
PoC
No
Published
2024-11-15
Modified
2024-11-15
First seen
2026-08-07
Aliases
EUVD-2024-3253, GHSA-GFWR-XQMJ-J27V
Products
librenms:librenms < 24.10.0
Sources
euvd EUVD-2024-3253

Description

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users' sessions, compromising their accounts and enabling unauthorized actions. This vulnerability is fixed in 24.10.0.

References