In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
librenms librenms |