216.73.216.197

CVE-2025-65013

· Published 18/11/2025 23:15 · Modified 20/11/2025 16:17

Labels: CVE-2025-65013 2025-11-18CVE-2025-65013CWE-79[email protected]

Essential information

Published
18/11/2025 23:15
Modified
20/11/2025 16:17
Author
Creator
CVSS
6.2 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

CVSS metrics

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the HTTP response without proper output encoding or sanitization, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript execution in the victim’s browser. This issue has been patched in version 25.11.0.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
librenms / librenms cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

References