Логотип exploitDog
bind:CVE-2025-69848
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69848

Количество 3

Количество 3

nvd логотип

CVE-2025-69848

6 дней назад

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-69848

6 дней назад

NetBox is an open-source infrastructure resource modeling and IP addre ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m2rq-533f-3phc

6 дней назад

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69848

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.

CVSS3: 6.1
0%
Низкий
6 дней назад
debian логотип
CVE-2025-69848

NetBox is an open-source infrastructure resource modeling and IP addre ...

CVSS3: 6.1
0%
Низкий
6 дней назад
github логотип
GHSA-m2rq-533f-3phc

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.

CVSS3: 6.1
0%
Низкий
6 дней назад

Уязвимостей на страницу