CVE-2023-36234: XSS
Published Sep 20, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.
Affected Software
2 affected components
netbox Netbox=3.5.1
Netbox Project Netbox=3.5.1
Event History
Sep 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-36234?
CVE-2023-36234 is a Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1 that allows attackers to execute arbitrary code.
2
How severe is CVE-2023-36234?
CVE-2023-36234 has a severity rating of medium, with a CVSS score of 5.4.
3
How does CVE-2023-36234 work?
CVE-2023-36234 allows attackers to execute arbitrary code by exploiting a Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1 through the Name field in the device-roles/add function.
4
What software is affected by CVE-2023-36234?
Netbox 3.5.1 is affected by CVE-2023-36234.
5
How can I fix CVE-2023-36234?
To fix CVE-2023-36234, it is recommended to update Netbox to a version that addresses the Cross Site Scripting (XSS) vulnerability.