Medium severity6.1NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026
CVE-2018-18478
CVE-2018-18478
Description
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and html/includes/forms/edit-dashboard.inc.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
librenms/librenmsPackagist | < 1.44 | 1.44 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/librenms/librenms/issues/9170nvdExploitThird Party AdvisoryWEB
- hackpuntes.com/cve-2018-18478-libre-nms-1-43-cross-site-scripting-persistente/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-9m82-f3wx-p625ghsaADVISORY
- github.com/librenms/librenms/pull/9171nvdThird Party AdvisoryWEB
- github.com/librenms/librenms/releases/tag/1.44nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-18478ghsaADVISORY
- hackpuntes.com/cve-2018-18478-libre-nms-1-43-cross-site-scripting-persistenteghsaWEB
News mentions
0No linked articles in our index yet.