GHSA-3jh2-wmv7-m932
GitHub Security Advisory
LibreNMS stored Cross-site Scripting via Schedule Maintenance `Title` parameter
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
LibreNMS versions 22.8.0 and prior allow attackers to execute arbitrary JavaScript code via the Schedule Maintenance `Title` parameter. A patch is available and anticipated to be part of version 22.9.0.
Affected Packages
Packagist
librenms/librenms
Affected versions:
0
(fixed in 22.9.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.