CVE-2023-33789: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Contact Groups (/tenancy/contact-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-33789.
What is the severity of CVE-2023-33789?
The severity of CVE-2023-33789 is medium.
What is the affected software for CVE-2023-33789?
The affected software for CVE-2023-33789 is Netbox v3.5.1.
How does CVE-2023-33789 work?
CVE-2023-33789 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name field in the Create Contact Groups function of Netbox.
Is there any fix available for CVE-2023-33789?
There is no specific fix or patch available for CVE-2023-33789 at the moment, but it is recommended to update Netbox to the latest version or apply any patches provided by the vendor.