First published: Wed Nov 03 2021(Updated: )
LibreNMS through 21.10.2 allows XSS via a widget title.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/librenms/librenms | <=21.10.2 | 21.11.0 |
Librenms Librenms | <=21.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43324 is a vulnerability in LibreNMS that allows XSS (Cross-Site Scripting) attacks via a widget title.
CVE-2021-43324 has a severity rating of medium with a CVSS score of 6.1.
The XSS vulnerability in CVE-2021-43324 can be exploited by injecting malicious scripts into the widget title, which will be executed when viewed by a user.
LibreNMS versions up to and including 21.10.2 are affected by CVE-2021-43324.
To fix CVE-2021-43324, it is recommended to update LibreNMS to version 21.11.0 or later.