-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| librenms/librenms | composer | >= 24.9.0, < 24.11.0 | 24.11.0 |
The vulnerability stems from unsanitized usage of displayName()/shortDisplayName() outputs in multiple templating contexts. The patch adds htmlentities() and strip_tags() to these locations. High-confidence entries directly map to Display Name XSS vectors described in advisories, while PortsController.ifAlias handling is marked medium confidence as it's a secondary vector.
Ongoing coverage of React2Shell