CVE-2024-40736: XSS
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/add.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40736?
CVE-2024-40736 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-40736?
To mitigate CVE-2024-40736, upgrade Netbox to version 4.0.4 or later as the vulnerability has been patched in those releases.
What are the potential impacts of CVE-2024-40736?
If exploited, CVE-2024-40736 allows attackers to execute arbitrary web scripts or HTML, potentially leading to unauthorized actions on behalf of users.
Where is CVE-2024-40736 located in the application?
CVE-2024-40736 specifically affects the Name parameter at the /dcim/power-outlets/add endpoint in Netbox version 4.0.3.
Who is affected by CVE-2024-40736?
Any user running Netbox version 4.0.3 is vulnerable to CVE-2024-40736, which can impact both internal and external users.