Medium severity5.4NVD Advisory· Published Sep 8, 2021· Updated Jun 17, 2026
CVE-2021-31274
CVE-2021-31274
Description
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
librenms/librenmsPackagist | < 21.3.0 | 21.3.0 |
Affected products
3- LibreNMS/LibreNMSdescription
Patches
Vulnerability mechanics
References
4- github.com/librenms/librenms/pull/12739nvdPatchThird Party AdvisoryWEB
- community.librenms.org/t/vulnerability-report-cross-site-scripting-xss-in-the-api-access-page/15431nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-2r2w-jrh2-p4grghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-31274ghsaADVISORY
News mentions
0No linked articles in our index yet.