CVE-2025-68614
Last modified
CVE-2025-68614 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. EPSS estimates a 3.42% chance of exploitation in the next 30 days.
Description
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Librenms | Librenms | < 25.12.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-68614?
How severe is CVE-2025-68614?
How do I fix CVE-2025-68614?
Are you affected by CVE-2025-68614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
