VYPR
Medium severity5.4NVD Advisory· Published Aug 28, 2019· Updated Jun 17, 2026

CVE-2019-15230

CVE-2019-15230

Description

LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.

Affected products

3
  • Librenms/Librenms2 versions
    cpe:2.3:a:librenms:librenms:1.54:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:librenms:librenms:1.54:*:*:*:*:*:*:*
    • (no CPE)range: =1.54
  • LibreNMS/LibreNMSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.