First published: Thu Dec 05 2024(Updated: )
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/librenms/librenms | >=24.9.0<24.11.0 | 24.11.0 |
LibreNMS | >=24.9.0<=24.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53457 is classified as a stored cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
To resolve CVE-2024-53457, upgrade LibreNMS to version 24.11.0 or later.
CVE-2024-53457 affects LibreNMS versions from 24.9.0 to 24.10.0.
Yes, CVE-2024-53457 could potentially allow an attacker to steal sensitive information through malicious scripts.
CVE-2024-53457 can be exploited by injecting crafted payloads into the Display Name parameter, making it a low-barrier vulnerability for attackers.