CVE-2023-37625: XSS
Published Aug 10, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.
Affected Software
2 affected components
netbox Netbox=3.4.7
Netbox Project Netbox=3.4.7
Event History
Aug 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37625?
CVE-2023-37625 has a medium severity rating due to its potential for executing arbitrary web scripts.
2
How do I fix CVE-2023-37625?
To fix CVE-2023-37625, update Netbox to the latest version that addresses this vulnerability.
3
Which versions of Netbox are affected by CVE-2023-37625?
CVE-2023-37625 affects Netbox version 3.4.7.
4
What is the impact of exploiting CVE-2023-37625?
Exploiting CVE-2023-37625 allows attackers to execute stored XSS attacks by injecting malicious scripts into Custom Link templates.
5
Is there a workaround for CVE-2023-37625 until a fix is applied?
Disabling the use of Custom Link templates can serve as a temporary workaround for CVE-2023-37625.