Back to Database
Status published
High
CVE-2024-32479
LibreNMS's Improper Sanitization on Service template name leads to Stored XSS
Vulnerability Description
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32479
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/librenms/librenms/security/advisories/GHSA-72m9-7c8x-pmmw
- https://github.com/librenms/librenms/commit/19344f0584d4d6d4526fdf331adc60530e3f685b
- https://github.com/librenms/librenms/blob/a61c11db7e8ef6a437ab55741658be2be7d14d34/app/Http/Controllers/ServiceTemplateController.php#L67C23-L67C23
More from librenms
View All →CVE-2025-68614
LibreNMS Alert Rule API Cross-Site Scripting Vulnerability
Medium
4.3
CVE-2025-65093
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Medium
5.5
CVE-2025-65014
LibreNMS has Weak Password Policy
Low
3.7
CVE-2025-65013
LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`
Medium
6.2
CVE-2025-62412
LibreNMS alert-rules Cross-Site Scripting Vulnerability
Low
3.8
Affected Vendor
librenms
View all reports →Affected Software
librenms
Vulnerable Versions:
< 24.4.0
Timeline
Official Publish:
April 22nd, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H