CVE-2024-40732: XSS
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/add/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40732?
CVE-2024-40732 has been classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-40732?
To fix CVE-2024-40732, upgrade to a patched version of Netbox that addresses this XSS vulnerability.
What does CVE-2024-40732 affect?
CVE-2024-40732 affects Netbox version 4.0.3, specifically targeting the Name parameter in the /dcim/rear-ports/add/ endpoint.
Can CVE-2024-40732 allow arbitrary script execution?
Yes, CVE-2024-40732 allows attackers to execute arbitrary web scripts or HTML due to the XSS vulnerability.
What is the exploit vector for CVE-2024-40732?
The exploit vector for CVE-2024-40732 involves injecting a crafted payload into the Name parameter at the specific endpoint in Netbox.