Vulnerability record · CVE-2022-4069 · published 20 November 2022
CVE-2022-4069: LibreNMS stored XSS in web interface before 22.10.0
Librenms · Librenms
LibreNMS versions prior to 22.10.0 contain a generic cross-site scripting flaw (CWE-79) in the web application. The vulnerability requires high privileges and user interaction, and the CVSS scope change indicates the injected script can affect resources beyond the vulnerable component. It matters because an authenticated high-privilege user can plant script that executes in the context of other users viewing the affected page.
Description
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it Medium (4.8) and exploitation requires high privileges plus user interaction, though the very high EPSS score warrants prompt patching.
What it is
LibreNMS versions prior to 22.10.0 contain a generic cross-site scripting flaw (CWE-79) in the web application. The vulnerability requires high privileges and user interaction, and the CVSS scope change indicates the injected script can affect resources beyond the vulnerable component. It matters because an authenticated high-privilege user can plant script that executes in the context of other users viewing the affected page.
Impact
An attacker with the required privileges can inject script that runs in a victim's browser session, potentially stealing session data or performing actions as the victim. The CVSS confidentiality and integrity impacts are both rated Low, so direct data compromise is limited.
Attack surface
Reached over the network through the LibreNMS web interface (AV:N). Exploitation requires high privileges (PR:H) and victim user interaction (UI:R), so it is not an unauthenticated or zero-click issue.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is very high (0.93343, 99.833rd percentile), but that score alone does not confirm active exploitation.
What to do
- Upgrade LibreNMS to 22.10.0 or later, applying the patch commit 8383376f1355812e09ec0c2af67f6d46891b7ba7.
- Restrict administrative and high-privilege LibreNMS accounts to trusted users and enforce least privilege.
- Apply output encoding and input sanitization for user-supplied content in the web interface if backporting is required.
- Deploy a content security policy and browser-side XSS protections to limit script execution impact.
Detection
- Review LibreNMS web server and application logs for suspicious script payloads in request parameters or stored fields.
- Monitor for unexpected JavaScript or HTML content appearing in LibreNMS pages viewed by multiple users.
- Alert on anomalous authenticated sessions or actions originating from high-privilege accounts outside normal patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/librenms/librenms/commit/8383376f1355812e09ec0c2af67f6d46891b7ba7 | PatchThird Party Advisory |
| https://huntr.dev/bounties/a9925d98-dac4-4c3c-835a-d93aeecfb2c5 | Permissions RequiredThird Party Advisory |
| https://github.com/librenms/librenms/commit/8383376f1355812e09ec0c2af67f6d46891b7ba7 | PatchThird Party Advisory |
| https://huntr.dev/bounties/a9925d98-dac4-4c3c-835a-d93aeecfb2c5 | Permissions RequiredThird Party Advisory |
Track CVE-2022-4069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-4069), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.