← Vulnerability feed

Vulnerability record · CVE-2023-4347 · published 15 August 2023

CVE-2023-4347: LibreNMS reflected XSS before 23.8.0

Librenms · Librenms

LibreNMS versions prior to 23.8.0 contain a reflected cross-site scripting flaw (CWE-79) in the web interface. An attacker who can get a logged-in user to open a crafted link can execute script in that user's browser session. The issue is fixed in 23.8.0.

5.4 CVSS 3.1 Medium EPSS 70% · top 0.6% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityPublic exploit reference and very high EPSS (0.697, 99.3rd percentile) raise the risk despite the medium CVSS score and required user interaction.

What it is

LibreNMS versions prior to 23.8.0 contain a reflected cross-site scripting flaw (CWE-79) in the web interface. An attacker who can get a logged-in user to open a crafted link can execute script in that user's browser session. The issue is fixed in 23.8.0.

Impact

An attacker can run arbitrary JavaScript in the context of an authenticated LibreNMS user, potentially stealing session cookies or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network through the LibreNMS web interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the victim must be authenticated and click or open a crafted link.

Exploitation

Not listed in CISA KEV, but a public exploit reference exists (huntr.dev bounty tagged Exploit) and EPSS is 0.697 (99.3rd percentile), indicating high predicted exploitation activity.

What to do

  • Upgrade LibreNMS to 23.8.0 or later, which contains the patch commit 91c57a1ee54631e071b6b0c952d99c8ee892e824.
  • If immediate upgrade is not possible, restrict access to the LibreNMS web interface to trusted networks or VPN.
  • Deploy a web application firewall or content security policy that blocks reflected script execution.
  • Educate users not to open untrusted links while logged into LibreNMS.

Detection

  • Search web server and proxy logs for requests containing script payloads in query strings or parameters to LibreNMS endpoints.
  • Monitor for anomalous JavaScript or HTML tags in LibreNMS request parameters.
  • Review authentication logs for session anomalies or unexpected actions following suspicious link clicks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-4070Librenms insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.EPSS 0.65%9.8CVE-2022-29712Librenms command injection vulnerabilityLibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.EPSS 1.7%9.8CVE-2021-44278Librenms path traversal vulnerabilityLibrenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.EPSS 1.5%9.8CVE-2019-10665Librenms injection vulnerabilityAn issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…EPSS 1.5%9.8CVE-2018-20434LibreNMS addhost OS command injection via community parameterLibreNMS 1.46 fails to sanitize the $_POST['community'] parameter in html/pages/addhost.inc.php when creating a new device, and the value is later mi…EPSS 71%analysed9.3CVE-2026-26988Librenms sql injection vulnerabilityLibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…EPSS 0.48%9.2CVE-2026-86426Librenms improper authentication vulnerabilityLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endp…EPSS 3.9%9.1CVE-2024-51092Librenms os command injection vulnerabilityLibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2023-4347), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.