← All CVEs

CVE-2024-32479

high · 7.1

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.

7.1
CVSS
34.1%
EPSS (exploit prob.)
98th
EPSS percentile
2024-04-22
Published

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
librenmslibrenms< 24.4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-32479