THREAT OPS › Threat News › [GHSA] GHSA-7w8c-qgxg-m7jx (high) — LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
[GHSA] GHSA-7w8c-qgxg-m7jx (high) — LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
GHSA-7w8c-qgxg-m7jx Severity: high CVE: None
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
## Summary
Multiple legacy PHP template files in LibreNMS directly output SNMP-sourced and syslog-sourced data into HTML without escaping. An attacker who controls a monitored network device (via compromised SNMP agent or syslog sender) can inject arbitrary JavaScript that executes when a
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- https://evil.com/url
Original source: https://github.com/advisories/GHSA-7w8c-qgxg-m7jx