CyberRota Analysis
AI-GeneratedLibreNMS versions prior to 26.3.1 are vulnerable to a stored cross-site scripting (XSS) flaw in legacy PHP templates, allowing attackers to inject malicious JavaScript via SNMP interface descriptions or syslog program fields. This vulnerability can lead to the execution of arbitrary scripts when authenticated users access affected pages, potentially compromising user data and session integrity. Organizations using LibreNMS should prioritize patching to mitigate the risk of exploitation, especially those managing network devices that could be targeted by attackers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.