CVE-2023-4347: Cross-site Scripting (XSS) - Reflected in librenms/librenms
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms 23.7.0 and prior. A patch is available at commit 91c57a1ee54631e071b6b0c952d99c8ee892e824 and anticiapted to be part of version 23.8.0.
Other sources
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4347?
The severity of CVE-2023-4347 is high with a CVSS score of 7.6.
How does CVE-2023-4347 affect Librenms version 23.7.0?
CVE-2023-4347 affects Librenms version 23.7.0 and prior with reflected cross-site scripting (XSS) vulnerability.
Is there a patch available for CVE-2023-4347?
Yes, a patch is available at commit 91c57a1ee54631e071b6b0c952d99c8ee892e824 and is anticipated to be part of version 23.8.0.
Where can I find more information about CVE-2023-4347?
You can find more information about CVE-2023-4347 at the following references: [link1](https://github.com/librenms/librenms/commit/91c57a1ee54631e071b6b0c952d99c8ee892e824), [link2](https://huntr.dev/bounties/1f78c6e1-2923-46c5-9376-4cc5a8f1152f), [link3](https://nvd.nist.gov/vuln/detail/CVE-2023-4347).
What is the Common Weakness Enumeration (CWE) for CVE-2023-4347?
The Common Weakness Enumeration (CWE) for CVE-2023-4347 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).