CVE-2023-33786: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Circuit Types (/circuits/circuit-types/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33786?
CVE-2023-33786 has a medium severity rating due to its potential to allow attackers to execute arbitrary scripts.
How do I fix CVE-2023-33786?
To fix CVE-2023-33786, upgrade to a patched version of Netbox that resolves this stored XSS vulnerability.
What are the potential impacts of CVE-2023-33786?
The impacts of CVE-2023-33786 include unauthorized script execution, which can lead to data theft or session hijacking.
Which versions of Netbox are affected by CVE-2023-33786?
CVE-2023-33786 affects Netbox version 3.5.1 specifically.
Is CVE-2023-33786 a remote vulnerability?
Yes, CVE-2023-33786 can be exploited remotely by injecting malicious scripts through the Name field in the Create Circuit Types function.