CVE-2022-4068 affects LibreNMS, allowing a low-privileged user to re-enable their own account if an administrator disabled it, provided they maintain a valid session. More critically, the vulnerability includes a stored Cross-Site Scripting (XSS) flaw (CWE-79) in the admin user overview due to improper username sanitization. This XSS allows an attacker to execute arbitrary JavaScript in an administrator's browser, potentially leading to unauthorized actions. Rated Medium severity with a CVSS score of 5.4, the attack requires low privileges and user interaction (UI:R), but its impact is limited to partial confidentiality and integrity (C:L/I:L). The EPSS score of 0.54367 indicates a higher-than-average probability of exploitation compared to most CVEs. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received no community discussion or media coverage, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 22.10.0CPE matchmatch criteria | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.