THREAT OPS › Threat News › [GHSA] GHSA-7gww-x7fh-jf9j (high) — LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
[GHSA] GHSA-7gww-x7fh-jf9j (high) — LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
GHSA-7gww-x7fh-jf9j Severity: high CVE: None
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
### Summary The Oxidized integration URL (`oxidized.url`) is admin-configurable. LibreNMS fetches device info and version history from that URL and renders JSON fields (`name`, `ip`, `model`, `author`, commit message) into HTML without `htmlspecialchars()`. An
Original source: https://github.com/advisories/GHSA-7gww-x7fh-jf9j