Vulnerability record · CVE-2022-3562 · published 20 November 2022
CVE-2022-3562: LibreNMS stored XSS before 22.10.0
Librenms · Librenms
LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that is stored and later rendered to other users, which matters because it can run in the context of higher-privileged sessions.
Description
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, though the very high EPSS score warrants prompt patching.
What it is
LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that is stored and later rendered to other users, which matters because it can run in the context of higher-privileged sessions.
Impact
An attacker can execute arbitrary script in the browser of a victim who views the injected content, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with low privileges required (PR:L) and user interaction needed (UI:R) for the victim to trigger the stored payload. No unauthenticated access is implied by the vector.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is very high (0.94216, 99.8th percentile), and references include a patch commit and a huntr bounty marked Permissions Required.
What to do
- Upgrade LibreNMS to 22.10.0 or later, applying the referenced patch commit.
- Restrict accounts and permissions so only trusted users can create or edit content that is rendered to others.
- Apply output encoding and input sanitization for stored user-supplied fields.
- Monitor for suspicious script content in stored fields and review recent changes by low-privileged accounts.
Detection
- Search application logs and stored content for script tags or event handlers in user-supplied fields.
- Alert on anomalous session activity or requests originating from pages containing stored user content.
- Review huntr bounty and patch commit details to build targeted signatures for the affected input paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/librenms/librenms/commit/43cb72549d90e338f902b359a83c23d3cb5a2645 | PatchThird Party Advisory |
| https://huntr.dev/bounties/bb9f76db-1314-44ae-9ccc-2b69679aa657 | Permissions RequiredThird Party Advisory |
| https://github.com/librenms/librenms/commit/43cb72549d90e338f902b359a83c23d3cb5a2645 | PatchThird Party Advisory |
| https://huntr.dev/bounties/bb9f76db-1314-44ae-9ccc-2b69679aa657 | Permissions RequiredThird Party Advisory |
Track CVE-2022-3562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3562), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.