CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*

History

30 Jun 2025, 14:50

Type Values Removed Values Added
CPE cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*
References () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - Release Notes
References () https://github.com/tu3n4nh/netbox/issues/1 - () https://github.com/tu3n4nh/netbox/issues/1 - Exploit, Issue Tracking
First Time Netbox
Netbox netbox

10 Feb 2025, 22:15

Type Values Removed Values Added
Summary (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

23 Sep 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de cross site scripting (XSS) almacenado en NetBox 4.1.0 dentro de la función "Historial de configuración" del panel "Administración" a través de una acción Agregar en /core/config-revisions/. Un usuario autenticado puede inyectar código JavaScript o HTML arbitrario en el campo "Banner superior".
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

22 Sep 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-22 02:15

Updated : 2025-06-30 14:50


NVD link : CVE-2024-47226

Mitre link : CVE-2024-47226

CVE.ORG link : CVE-2024-47226


JSON object : View

Products Affected

netbox

  • netbox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')