XSS on the parameters:/addhost -> param: community
of Librenms versions 24.10.1 (https://github.com/librenms/librenms) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.
Proof of Concept:
Navigate to the /addhost path.
Fill in all required fields.
In the Community field, enter the following payload: "><img src=a onerror="alert(1)">.
Submit the form to save changes.
5 The script will execute when the error alert "No reply with community + payload" appears.
Impact:
Execution of Malicious Code
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-01-16T17:33:10Z",
"nvd_published_at": "2025-01-16T23:15:08Z",
"severity": "MODERATE"
}