First published: Wed Sep 08 2021(Updated: )
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Librenms Librenms | <21.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31274 is a stored XSS vulnerability identified in LibreNMS < 21.3.0, allowing arbitrary JavaScript code execution.
CVE-2021-31274 affects LibreNMS versions less than 21.3.0 by enabling stored XSS attacks via the API Access page.
The severity of CVE-2021-31274 is medium with a CVSS score of 5.4.
To fix CVE-2021-31274, upgrade LibreNMS to version 21.3.0 or higher.
You can find more information about CVE-2021-31274 on the NIST National Vulnerability Database (NVD) page and the GitHub pull request and community discussion linked in the references.