CVE-2024-52526: LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php
A Stored Cross-Site Scripting (XSS) vulnerability in the “Services” tab of the Device page allows authenticated users to inject arbitrary JavaScript through the “descr” parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users’ sessions, potentially compromising their accounts and enabling unauthorized actions.
References
Detect and mitigate CVE-2024-52526 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →