CVE-2024-53457: XSS
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53457?
CVE-2024-53457 is classified as a stored cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
How do I fix CVE-2024-53457?
To resolve CVE-2024-53457, upgrade LibreNMS to version 24.11.0 or later.
What versions of LibreNMS are affected by CVE-2024-53457?
CVE-2024-53457 affects LibreNMS versions from 24.9.0 to 24.10.0.
Can CVE-2024-53457 lead to data theft?
Yes, CVE-2024-53457 could potentially allow an attacker to steal sensitive information through malicious scripts.
Is CVE-2024-53457 easy to exploit?
CVE-2024-53457 can be exploited by injecting crafted payloads into the Display Name parameter, making it a low-barrier vulnerability for attackers.