CVE-2025-23198

CVSS 3.1 Score 4.6 of 10 (medium)

Attack Complexity low
Confidentiality low
Integrity low
Privileges Required low
Availability none
Scope unchanged

Details

Published Jan 16, 2025
CWE ID 79

Summary

CVE-2025-23198 is a stored Cross-Site Scripting (XSS) vulnerability affecting versions of the Librenms network monitoring system up to 24.10.1. This issue allows remote attackers to inject malicious scripts into the param "display" on the /device/$DEVICE_ID/edit page. When a user views or interacts with the affected page, the malicious script executes, potentially leading to unauthorized actions or data exposure. The vulnerability has been addressed in version 24.11.0. Users are advised to upgrade as soon as possible, as there are no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share