ZDI-25-1182: LibreNMS Alert Rule API Cross-Site Scripting Vulnerability
This vulnerability allows remote attackers to execute arbitrary script on affected installations of LibreNMS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2025-68614.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1182?
The vulnerability ZDI-25-1182 has been assigned a CVSS rating of 4.3.
How do I fix ZDI-25-1182?
To fix the vulnerability ZDI-25-1182, ensure that you're using the latest version of LibreNMS and apply any relevant patches.
Who can exploit ZDI-25-1182?
Authentication is required for an attacker to exploit the vulnerability ZDI-25-1182.
What type of vulnerability is ZDI-25-1182?
ZDI-25-1182 allows remote attackers to execute arbitrary scripts on affected installations of LibreNMS.
What are the implications of ZDI-25-1182?
Successful exploitation of ZDI-25-1182 could lead to the execution of arbitrary scripts, potentially compromising the affected system.