CVE-2024-32479
PHP vulnerability analysis and mitigation

Overview

CVE-2024-32479 affects LibreNMS, an open-source PHP/MySQL/SNMP-based network monitoring system. The vulnerability, discovered in versions prior to 24.4.0, involves improper sanitization of the Service template name, which can lead to stored Cross-site Scripting (XSS). The issue was fixed in version 24.4.0 (GitHub Advisory).

Technical details

The vulnerability exists in the ServiceTemplateController.php file where there is improper sanitization of the Service template name that reflects in the delete button onclick event. The unsanitized value can be modified and crafted as arbitrary JavaScript code. The vulnerability has received a CVSS v3.1 base score of 7.1 HIGH (Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H) from GitHub, while NIST assigned a score of 5.4 MEDIUM (NVD, GitHub Advisory).

Impact

The Cross-site Scripting vulnerability can lead to cookie theft and enables attackers to execute arbitrary features within the application context. The high severity ratings for confidentiality, integrity, and availability indicate potential significant impact on system security (GitHub Advisory).

Exploitability

A proof of concept exists where an attacker can inject malicious JavaScript code through the template name field. The attack requires network access, high attack complexity, low privileges, and user interaction. The vulnerability can be triggered by entering crafted input in the service template name field under /services/templates (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in LibreNMS version 24.4.0. Users should upgrade to this version or later to mitigate the risk. The fix involves proper handling of user input in the Service Templates functionality (GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management