CVE-2024-40742: XSS
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/add.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40742?
CVE-2024-40742 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How does CVE-2024-40742 affect affected versions of Netbox?
CVE-2024-40742 allows attackers to execute arbitrary web scripts or HTML by injecting crafted payloads into the circuit ID parameter.
How do I fix CVE-2024-40742?
To fix CVE-2024-40742, upgrade to Netbox version 4.0.4 or later, which patches the vulnerable circuit ID parameter.
Where can I find more information about CVE-2024-40742?
More information about CVE-2024-40742 can be found on security advisories and repositories related to Netbox.
Is CVE-2024-40742 a common vulnerability in web applications?
Yes, cross-site scripting vulnerabilities like CVE-2024-40742 are common in web applications, especially when user input is not adequately sanitized.