CVE-2024-40730: XSS
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40730?
CVE-2024-40730 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-40730?
To fix CVE-2024-40730, upgrade Netbox to version 4.0.4 or later, which addresses the XSS vulnerability.
What does CVE-2024-40730 affect?
CVE-2024-40730 affects Netbox version 4.0.3, specifically in the Name parameter at /dcim/interfaces/{id}/edit/.
How can CVE-2024-40730 be exploited?
CVE-2024-40730 can be exploited by attackers injecting crafted payloads into the Name parameter, allowing the execution of arbitrary web scripts.
Is CVE-2024-40730 present in earlier versions of Netbox?
No, CVE-2024-40730 specifically affects Netbox version 4.0.3; earlier versions are not impacted by this vulnerability.