A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended. |
Mon, 23 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lenel
Lenel netbox |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:lenel:netbox:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lenel
Lenel netbox |
|
Metrics |
cvssV3_1
|
Sun, 22 Sep 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-11T21:43:56.176Z
Reserved: 2024-09-22T00:00:00.000Z
Link: CVE-2024-47226

Updated: 2024-09-23T14:58:04.686Z

Status : Awaiting Analysis
Published: 2024-09-22T02:15:02.797
Modified: 2025-02-10T22:15:35.383
Link: CVE-2024-47226

No data.