CVE-2024-50352: LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.php
A Stored Cross-Site Scripting (XSS) vulnerability in the “Services” section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the “name” parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users’ sessions, potentially compromising their accounts and enabling unauthorized actions.
References
Detect and mitigate CVE-2024-50352 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →