CVE-2023-33787: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Tenant Groups (/tenancy/tenant-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33787?
CVE-2023-33787 is a stored cross-site scripting (XSS) vulnerability in Netbox v3.5.1.
What is the severity of CVE-2023-33787?
The severity of CVE-2023-33787 is medium with a CVSS score of 5.4.
How does CVE-2023-33787 affect Netbox?
CVE-2023-33787 affects Netbox v3.5.1 and allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Is there a fix available for CVE-2023-33787?
As of now, no specific fix has been mentioned for CVE-2023-33787. Consider updating to the latest version of Netbox or implementing appropriate mitigations.
Where can I find more information about CVE-2023-33787?
You can find more information about CVE-2023-33787 at the following reference: https://github.com/anhdq201/netbox/issues/6