CVE-2023-33795: XSS
A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33795?
The severity of CVE-2023-33795 is medium with a CVSS score of 5.4.
How does CVE-2023-33795 impact Netbox v3.5.1?
CVE-2023-33795 allows attackers to execute arbitrary web scripts or HTML through a stored cross-site scripting (XSS) vulnerability in the Create Contact Roles function.
What software versions are affected by CVE-2023-33795?
Netbox v3.5.1 is affected by CVE-2023-33795.
How can I fix CVE-2023-33795?
There is currently no official fix for CVE-2023-33795. It is recommended to regularly update Netbox to the latest version when a patch becomes available.
Where can I find more information about CVE-2023-33795?
You can find more information about CVE-2023-33795 at the following link: [GitHub Issue](https://github.com/anhdq201/netbox/issues/15)