CVE-2023-33799: XSS
Published May 24, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
2 affected components
netbox Netbox=3.5.1
Netbox Project Netbox=3.5.1
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33799?
CVE-2023-33799 is considered a medium severity vulnerability due to its ability to execute arbitrary web scripts or HTML.
2
How do I fix CVE-2023-33799?
To fix CVE-2023-33799, users should upgrade to a patched version of Netbox beyond v3.5.1.
3
What type of vulnerability is CVE-2023-33799?
CVE-2023-33799 is classified as a stored cross-site scripting (XSS) vulnerability.
4
In which function does CVE-2023-33799 occur?
CVE-2023-33799 occurs in the Create Contacts function of Netbox.
5
What is the attack vector for CVE-2023-33799?
The attack vector for CVE-2023-33799 is through a crafted payload injected into the Name field when creating contacts.