CVE-2024-51497: LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php
A Stored Cross-Site Scripting (XSS) vulnerability in the “Custom OID” tab of a device allows authenticated users to inject arbitrary JavaScript through the “unit” parameter when creating a new OID. This vulnerability can lead to the execution of malicious code in the context of other users’ sessions, compromising their accounts and enabling unauthorized actions.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-51497 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →