Vulnerability Details CVE-2019-15230
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 55.0%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2019-15230
-
cpe:2.3:a:librenms:librenms:1.54