CVE-2024-56916

In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration History version or attempts to Add a new version, the XSS payload will trigger.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*

History

30 Jun 2025, 14:43

Type Values Removed Values Added
First Time Netbox
Netbox netbox
CPE cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*
References () https://github.com/netbox-community/netbox/releases/tag/v4.1.7 - () https://github.com/netbox-community/netbox/releases/tag/v4.1.7 - Release Notes
References () https://github.com/noxlumens/Vulnerability-Research/tree/main/CVE-2024-56916 - () https://github.com/noxlumens/Vulnerability-Research/tree/main/CVE-2024-56916 - Third Party Advisory, Exploit
References () https://www.youtube.com/watch?v=GC8-PUlu2i8 - () https://www.youtube.com/watch?v=GC8-PUlu2i8 - Exploit

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) En Netbox Community 4.1.7, una vez autenticado, la opción "Historial de Configuración > Agregar" es vulnerable a ataques de Cross-Site Scripting (XSS) debido a que el campo "valor actual" representa el HTML proporcionado por el usuario. Un atacante autenticado puede aprovechar esto para agregar JavaScript malicioso al campo "Cualquier banner". Al editar una versión del Historial de Configuración o intentar agregar una nueva versión, se activa el payload XSS.

24 Jun 2025, 20:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

24 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 18:15

Updated : 2025-06-30 14:43


NVD link : CVE-2024-56916

Mitre link : CVE-2024-56916

CVE.ORG link : CVE-2024-56916


JSON object : View

Products Affected

netbox

  • netbox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')