CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*

History

30 Jun 2025, 14:50

Type Values Removed Values Added
First Time Netbox
Netbox netbox
References () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - Release Notes
References () https://github.com/tu3n4nh/netbox/issues/1 - () https://github.com/tu3n4nh/netbox/issues/1 - Exploit, Issue Tracking
CPE cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*

10 Feb 2025, 22:15

Type Values Removed Values Added
Summary (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

23 Sep 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79
Summary
  • (es) Existe una vulnerabilidad de cross site scripting (XSS) almacenado en NetBox 4.1.0 dentro de la función "Historial de configuración" del panel "Administración" a través de una acción Agregar en /core/config-revisions/. Un usuario autenticado puede inyectar código JavaScript o HTML arbitrario en el campo "Banner superior".

22 Sep 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-22 02:15

Updated : 2025-06-30 14:50


NVD link : CVE-2024-47226

Mitre link : CVE-2024-47226

CVE.ORG link : CVE-2024-47226


JSON object : View

Products Affected

netbox

  • netbox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')