First published: Tue Aug 15 2023(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms 23.7.0 and prior. A patch is available at commit 91c57a1ee54631e071b6b0c952d99c8ee892e824 and anticiapted to be part of version 23.8.0.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Librenms Librenms | <23.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4347 is high with a CVSS score of 7.6.
CVE-2023-4347 affects Librenms version 23.7.0 and prior with reflected cross-site scripting (XSS) vulnerability.
Yes, a patch is available at commit 91c57a1ee54631e071b6b0c952d99c8ee892e824 and is anticipated to be part of version 23.8.0.
You can find more information about CVE-2023-4347 at the following references: [link1](https://github.com/librenms/librenms/commit/91c57a1ee54631e071b6b0c952d99c8ee892e824), [link2](https://huntr.dev/bounties/1f78c6e1-2923-46c5-9376-4cc5a8f1152f), [link3](https://nvd.nist.gov/vuln/detail/CVE-2023-4347).
The Common Weakness Enumeration (CWE) for CVE-2023-4347 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).