CVE-2025-23198
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2025-23198 is a stored Cross-Site Scripting (XSS) vulnerability affecting versions of the Librenms network monitoring system up to 24.10.1. This issue allows remote attackers to inject malicious scripts into the param "display" on the /device/$DEVICE_ID/edit page. When a user views or interacts with the affected page, the malicious script executes, potentially leading to unauthorized actions or data exposure. The vulnerability has been addressed in version 24.11.0. Users are advised to upgrade as soon as possible, as there are no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibreNMS
Affected Vendors
- LibreNMS