CVE-2019-25011: XSS
Published Dec 31, 2020
·Updated
NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.
Affected Software
2 affected components
netbox Netbox<=2.6.2
Netbox Project Netbox<=2.6.2
Event History
Dec 31, 2020
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
Description
Frequently Asked Questions
1
What is CVE-2019-25011?
CVE-2019-25011 is a vulnerability in NetBox through 2.6.2 that allows an authenticated user to conduct an XSS attack against an admin via a GFM-rendered field.
2
How severe is CVE-2019-25011?
CVE-2019-25011 has a severity rating of medium with a CVSS score of 5.4.
3
How can an authenticated user exploit CVE-2019-25011?
An authenticated user can exploit CVE-2019-25011 by conducting an XSS attack against an admin via a GFM-rendered field.
4
Which version of NetBox is affected by CVE-2019-25011?
NetBox version up to and including 2.6.2 is affected by CVE-2019-25011.
5
Is there a fix available for CVE-2019-25011?
Yes, it is recommended to update NetBox to a version that is not affected by CVE-2019-25011.