CVE-2023-33800: XSS
Published May 24, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Affected Software
2 affected components
Netbox Project Netbox=3.5.1
netbox Netbox=3.5.1
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33800?
CVE-2023-33800 is considered a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-33800?
To fix CVE-2023-33800, update Netbox to the latest version that addresses this stored XSS vulnerability.
3
What systems are affected by CVE-2023-33800?
CVE-2023-33800 specifically affects Netbox version 3.5.1.
4
What kind of attack can be executed using CVE-2023-33800?
CVE-2023-33800 allows attackers to execute arbitrary web scripts or HTML through a crafted payload in the Name field.
5
Is user input involved in the CVE-2023-33800 vulnerability?
Yes, user input in the Name field is exploited in CVE-2023-33800 to perform stored cross-site scripting.