LibreNMS 是一个网络监控系统。在包括 26.4.0 及更早的版本中,Proxmox 应用程序视图存在反射型跨站脚本(XSS)漏洞,原因是用户提供的 和 GET 参数未经充分编码即被反射到页面标题中。 这些参数仅经过 处理后被写入页面标题,随后通过字符串插值写入行内 JavaScript 的 赋值语句中。因此,输入中的单引号可以终止 JavaScript 字符串,导致后续内容作为脚本执行。 攻击者若诱使已认证用户点击一个精心构造的链接,即可在该用户的会话中执行脚本,从而窃取会话数据等敏感信息。 该问题已在 2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55182 | 8.6 HIGH | LibreNMS: Remote Code Execution by Signal Alert Transportation Module |
| CVE-2026-80214 | 8.6 HIGH | LibreNMS Virtualisation Discovery Module RCE |
No comments yet