In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| librenms/librenms(Packagist) | 0 | 21.3.0 | N/A |
CVSS Metrics