CVE-2023-33793: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33793?
CVE-2023-33793 is a stored cross-site scripting (XSS) vulnerability in the Create Power Panels function of Netbox v3.5.1.
How does the stored cross-site scripting (XSS) vulnerability in Create Power Panels function occur?
The stored XSS vulnerability occurs when an attacker injects a crafted payload into the Name field of the Create Power Panels function.
What is the potential impact of CVE-2023-33793?
The vulnerability allows attackers to execute arbitrary web scripts or HTML, which can lead to unauthorized access, data theft, and other malicious activities.
What software is affected by CVE-2023-33793?
Netbox v3.5.1 is affected by CVE-2023-33793.
How can I fix CVE-2023-33793?
Update Netbox to the latest version available, which includes a patch for the vulnerability.