Vulnerability record · CVE-2023-4347 · published 15 August 2023
CVE-2023-4347: LibreNMS reflected XSS before 23.8.0
Librenms · Librenms
LibreNMS versions prior to 23.8.0 contain a reflected cross-site scripting flaw (CWE-79) in the web interface. An attacker who can get a logged-in user to open a crafted link can execute script in that user's browser session. The issue is fixed in 23.8.0.
Description
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit reference and very high EPSS (0.697, 99.3rd percentile) raise the risk despite the medium CVSS score and required user interaction.
What it is
LibreNMS versions prior to 23.8.0 contain a reflected cross-site scripting flaw (CWE-79) in the web interface. An attacker who can get a logged-in user to open a crafted link can execute script in that user's browser session. The issue is fixed in 23.8.0.
Impact
An attacker can run arbitrary JavaScript in the context of an authenticated LibreNMS user, potentially stealing session cookies or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the LibreNMS web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the victim must be authenticated and click or open a crafted link.
Exploitation
Not listed in CISA KEV, but a public exploit reference exists (huntr.dev bounty tagged Exploit) and EPSS is 0.697 (99.3rd percentile), indicating high predicted exploitation activity.
What to do
- Upgrade LibreNMS to 23.8.0 or later, which contains the patch commit 91c57a1ee54631e071b6b0c952d99c8ee892e824.
- If immediate upgrade is not possible, restrict access to the LibreNMS web interface to trusted networks or VPN.
- Deploy a web application firewall or content security policy that blocks reflected script execution.
- Educate users not to open untrusted links while logged into LibreNMS.
Detection
- Search web server and proxy logs for requests containing script payloads in query strings or parameters to LibreNMS endpoints.
- Monitor for anomalous JavaScript or HTML tags in LibreNMS request parameters.
- Review authentication logs for session anomalies or unexpected actions following suspicious link clicks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/librenms/librenms/commit/91c57a1ee54631e071b6b0c952d99c8ee892e824 | Patch |
| https://huntr.dev/bounties/1f78c6e1-2923-46c5-9376-4cc5a8f1152f | ExploitThird Party Advisory |
| https://github.com/librenms/librenms/commit/91c57a1ee54631e071b6b0c952d99c8ee892e824 | Patch |
| https://huntr.dev/bounties/1f78c6e1-2923-46c5-9376-4cc5a8f1152f | ExploitThird Party Advisory |
Track CVE-2023-4347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-4347), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.