CVE-2024-49754: LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php
A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the “token” parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users’ sessions, compromising their accounts and enabling unauthorized actions.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-49754 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →