CVE-2025-23201
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 16, 2025
CWE ID 79
Summary
CVE-2025-23201 is a Cross-site Scripting (XSS) vulnerability affecting Librenms, a community-based network monitoring system. The flaw lies in the `/addhost` endpoint and the `community` parameter, allowing remote attackers to inject malicious scripts. Successful exploitation results in immediate execution of the malicious script when the targeted user views or interacts with the affected page. Potential consequences include unauthorized actions and data exposure. Librenms users are urged to upgrade to version 24.11.0 as a workaround is not available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- LibreNMS
Affected Vendors
- LibreNMS