A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
References
Link | Resource |
---|---|
https://github.com/netbox-community/netbox/releases/tag/v4.1.0 | Release Notes |
https://github.com/tu3n4nh/netbox/issues/1 | Exploit Issue Tracking |
Configurations
History
30 Jun 2025, 14:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:* | |
References | () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - Release Notes | |
References | () https://github.com/tu3n4nh/netbox/issues/1 - Exploit, Issue Tracking | |
First Time |
Netbox
Netbox netbox |
10 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended. |
23 Sep 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
22 Sep 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-22 02:15
Updated : 2025-06-30 14:50
NVD link : CVE-2024-47226
Mitre link : CVE-2024-47226
CVE.ORG link : CVE-2024-47226
JSON object : View
Products Affected
netbox
- netbox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')