CVE-2023-33797: XSS
Published May 24, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
2 affected components
netbox Netbox=3.5.1
Netbox Project Netbox=3.5.1
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this XSS vulnerability?
The vulnerability ID of this XSS vulnerability is CVE-2023-33797.
2
What is the severity level of CVE-2023-33797?
The severity level of CVE-2023-33797 is medium with a severity value of 5.4.
3
How does the XSS vulnerability in CVE-2023-33797 allow attackers to execute arbitrary web scripts or HTML?
The XSS vulnerability in CVE-2023-33797 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name field.
4
What is the affected software version of CVE-2023-33797?
The affected software version of CVE-2023-33797 is Netbox v3.5.1.
5
Is there a fix available for CVE-2023-33797?
To fix CVE-2023-33797, it is recommended to update to a version of Netbox that is not affected by this vulnerability.