Логотип exploitDog
bind:CVE-2024-47226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47226

Количество 3

Количество 3

nvd логотип

CVE-2024-47226

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-47226

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1 ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-725j-ffcc-fc53

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1 ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-725j-ffcc-fc53

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу