CVE-2023-33798: XSS
Published May 24, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
2 affected components
netbox Netbox=3.5.1
Netbox Project Netbox=3.5.1
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this XSS vulnerability?
The vulnerability ID of this XSS vulnerability is CVE-2023-33798.
2
What is the description of the vulnerability?
The vulnerability is a stored cross-site scripting (XSS) vulnerability in the Create Rack function of Netbox v3.5.1, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
3
What software is affected by this vulnerability?
The Netbox v3.5.1 software is affected by this vulnerability.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update Netbox to a version that is not affected by the XSS vulnerability.