Impact
A server‑side template injection in NetBox allows a low‑privileged user with the "Can add custom links" permission to embed the raw Django HttpRequest object into a custom link. By inserting request.COOKIES['sessionid'] or an authenticated API token into an image source tag, the attacker can force the victim’s session cookie or API token to be sent to an attacker‑controlled host when a privileged user views the link, enabling full account takeover. The weakness is represented by CWE-668 and CWE-79.
Affected Systems
NetBox Community Edition versions 2.9.5 through any release before 4.7.0 are affected. The issue applies to all installations that expose custom link templates in these releases. Upgrading to 4.7.0 or later removes the vulnerability.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is considered medium severity. No EPSS data is publicly available and the issue is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged user to craft a malicious custom link and a privileged user to view it; if privileged users routinely interact with custom links created by others, the attack can be performed without additional privileges, making the risk significant for organizations with many active accounts.
OpenCVE Enrichment