VYPR

Librenms

by Librenms

Source repositories

CVEs (122)

  • CVE-2021-31274MedSep 8, 2021
    risk 0.00cvss 5.4epss 0.01

    In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2018-18478MedOct 18, 2018
    risk 0.00cvss 6.1epss 0.02

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…

Page 7 of 7