CVE-2021-43324: XSS
Published Nov 3, 2021
·Updated
LibreNMS through 21.10.2 allows XSS via a widget title.
Affected Software
2 affected componentsFixes available
composer/librenms/librenms<=21.10.2
21.11.0
librenms librenms<=21.10.2
Remediation
Event History
Nov 3, 2021
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 8, 2021
Advisory Published
05:59 PM
Frequently Asked Questions
1
What is CVE-2021-43324?
CVE-2021-43324 is a vulnerability in LibreNMS that allows XSS (Cross-Site Scripting) attacks via a widget title.
2
How severe is CVE-2021-43324?
CVE-2021-43324 has a severity rating of medium with a CVSS score of 6.1.
3
How can the XSS vulnerability be exploited?
The XSS vulnerability in CVE-2021-43324 can be exploited by injecting malicious scripts into the widget title, which will be executed when viewed by a user.
4
What is the affected version of LibreNMS?
LibreNMS versions up to and including 21.10.2 are affected by CVE-2021-43324.
5
How can I fix CVE-2021-43324?
To fix CVE-2021-43324, it is recommended to update LibreNMS to version 21.11.0 or later.