CVE-2023-33788: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Providers (/circuits/providers/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33788?
The severity of CVE-2023-33788 is medium with a CVSS score of 5.4.
How does CVE-2023-33788 affect Netbox v3.5.1?
CVE-2023-33788 affects Netbox v3.5.1 by allowing attackers to execute arbitrary web scripts or HTML through a crafted payload injected into the Name field.
Is there a workaround for CVE-2023-33788?
There is no known workaround for CVE-2023-33788 at this time.
Are there any references for CVE-2023-33788?
Yes, you can find more information about CVE-2023-33788 at the following reference: https://github.com/anhdq201/netbox/issues/3
What is the Common Weakness Enumeration (CWE) for CVE-2023-33788?
The CWE for CVE-2023-33788 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').