CVE-2025-23198
LibreNMS Display Name Stored Cross-site Scripting vulnerability
描述
**Description:** XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display of Librenms versions 24.9.0, 24.10.0, and 24.10.1 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. **Proof of Concept:** 1. Add a new device through the LibreNMS interface. 2. Edit the newly created device by going to the "Device Settings" section. 3. In the "Display Name" field, enter the following payload: `"><script>alert(1)</script>`.  4. Save the changes. 5. The XSS payload triggers when accessing the "/apps" path (if an application was previously added).  **Additional PoC:** 1. In the "Display Name" field, enter the following payload: `"><img src onerror="alert(1)">`.  2. The XSS vulnerability is triggered when accessing the "/ports" path, and the payload executes when hovering over the modified value in the "Port" field.  - on `/device/$DEVICE_ID/ports/arp` path:  - on `/device/$DEVICE_ID/logs` path:  - on `/search/search=arp/` path:  **Impact:** Execution of Malicious Code
如何修補 CVE-2025-23198
要修補 CVE-2025-23198,請將受影響套件升級到下列已修補版本。
- —升級至 24.11.0 或更新版本
CVE-2025-23198 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。