CVE-2023-33785: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33785?
The severity of CVE-2023-33785 is medium with a CVSS score of 5.4.
What is the description of CVE-2023-33785?
CVE-2023-33785 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field of the Create Rack Roles function in Netbox v3.5.1.
How does CVE-2023-33785 affect Netbox?
CVE-2023-33785 affects Netbox v3.5.1.
Is there a fix for CVE-2023-33785?
The fix for CVE-2023-33785 is currently not available. It is recommended to update to a version that is not affected by this vulnerability.
What is CWE-79?
CWE-79 refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').