A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| librenms/librenms(Packagist) | 24.9.0 | 24.11.0 | N/A |
CVSS Metrics