Reflected XSS in librenms/librenms
Reported on
Jan 30th 2023
Description
Reflected Cross-Site Scripting (XSS) vulnerability in LibreNMS 22.12.0 - Fri Dec 30 2022 10:11:51 GMT+0100 allows attackers to execute arbitrary external javascript code in the browser affected from /ports/group parameter.
- Login
- Navigate PoC link
Proof of Concept
http://YOURSITE/ports/group=OOOOO%3C%2Fscript%3E%3Cscript%3Ealert(document.cookie)%3C%2Fscript%3E
Poc
Impact
This vulnerability allows attackers to hijack the user's current session, steal relevant information, deface website or direct users to malicious websites and allows attacker to use for further exploitation.
SECURITY.md
exists
10 months ago