CVE-2023-33791: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Provider Accounts (/circuits/provider-accounts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33791?
The severity of CVE-2023-33791 is medium with a severity value of 5.4.
How does the stored cross-site scripting (XSS) vulnerability in CVE-2023-33791 work?
The stored cross-site scripting (XSS) vulnerability in CVE-2023-33791 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name field of the Create Provider Accounts function in Netbox v3.5.1.
Which software versions are affected by CVE-2023-33791?
Netbox v3.5.1 is affected by CVE-2023-33791.
Is there a fix available for CVE-2023-33791?
Currently, there is no known fix available for CVE-2023-33791. It is recommended to update to a patched version of Netbox when it becomes available.
Where can I find more information about CVE-2023-33791?
More information about CVE-2023-33791 can be found at the following reference: https://github.com/anhdq201/netbox/issues/4