CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field.
Configurations

No configuration.

History

23 Sep 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79
Summary
  • (es) Existe una vulnerabilidad de cross site scripting (XSS) almacenado en NetBox 4.1.0 dentro de la función "Historial de configuración" del panel "Administración" a través de una acción Agregar en /core/config-revisions/. Un usuario autenticado puede inyectar código JavaScript o HTML arbitrario en el campo "Banner superior".

22 Sep 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-22 02:15

Updated : 2024-09-26 13:32


NVD link : CVE-2024-47226

Mitre link : CVE-2024-47226

CVE.ORG link : CVE-2024-47226


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')