Vulnerability record · CVE-2022-4067 · published 20 November 2022
CVE-2022-4067: LibreNMS stored XSS before 22.10.0
Librenms · Librenms
LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that executes in the browser of another user viewing the affected page. Because the script is stored, it can fire repeatedly against any user who loads the content.
Description
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityMedium CVSS but very high EPSS and a stored XSS that can compromise privileged sessions justify prompt patching.
What it is
LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that executes in the browser of another user viewing the affected page. Because the script is stored, it can fire repeatedly against any user who loads the content.
Impact
Successful exploitation lets the attacker run arbitrary JavaScript in a victim's session, enabling session theft, credential capture or actions performed as the victim. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with low privileges required (PR:L) and user interaction needed (UI:R), meaning a logged-in low-privileged user must get a victim to view the injected content. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.937 probability, 99.8th percentile), indicating elevated predicted exploitation activity. References include a patch commit and a huntr bounty marked Permissions Required; no public exploit code is cited in the record.
What to do
- Upgrade LibreNMS to 22.10.0 or later, applying the referenced patch commit.
- Restrict accounts and permissions so only trusted users can create or edit content rendered to others.
- Apply output encoding and input sanitization for stored user-supplied fields.
- Deploy a content security policy to limit script execution in the LibreNMS UI.
- Monitor for unexpected script content in stored records and review audit logs.
Detection
- Search LibreNMS data stores and logs for stored payloads containing script tags or event handlers.
- Monitor web logs for requests to LibreNMS pages that return injected script content.
- Alert on anomalous authenticated sessions or actions following views of user-generated content.
- Review huntr and patch commit details to build signatures for the specific injection point.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/librenms/librenms/commit/8e85698aa3aa4884c2f3d6c987542477eb64f07c | PatchThird Party Advisory |
| https://huntr.dev/bounties/3ca7023e-d95c-423f-9e9a-222a67a8ee72 | Permissions RequiredThird Party Advisory |
| https://github.com/librenms/librenms/commit/8e85698aa3aa4884c2f3d6c987542477eb64f07c | PatchThird Party Advisory |
| https://huntr.dev/bounties/3ca7023e-d95c-423f-9e9a-222a67a8ee72 | Permissions RequiredThird Party Advisory |
Track CVE-2022-4067 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-4067), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.