CVE-2025-23201

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 79

Summary

CVE-2025-23201 is a Cross-site Scripting (XSS) vulnerability affecting Librenms, a community-based network monitoring system. The flaw lies in the `/addhost` endpoint and the `community` parameter, allowing remote attackers to inject malicious scripts. Successful exploitation results in immediate execution of the malicious script when the targeted user views or interacts with the affected page. Potential consequences include unauthorized actions and data exposure. Librenms users are urged to upgrade to version 24.11.0 as a workaround is not available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share