CVE-2024-56916: XSS
In Netbox Community 4.1.7, once authenticated, Configuration History > Addis vulnerable to cross-site scripting (XSS) due to the current value field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration History version or attempts to Add a new version, the XSS payload will trigger.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56916?
CVE-2024-56916 has been classified as a medium severity vulnerability due to the risk of cross-site scripting (XSS).
How do I fix CVE-2024-56916?
To fix CVE-2024-56916, upgrade to the latest version of Netbox Community that contains the security patch addressing this vulnerability.
What specific component of Netbox Community is affected by CVE-2024-56916?
CVE-2024-56916 affects the Configuration History > Add feature in Netbox Community 4.1.7.
Who can exploit CVE-2024-56916?
An authenticated attacker who has access to the Configuration History feature can exploit CVE-2024-56916 to execute malicious scripts.
What impact does CVE-2024-56916 have on users?
CVE-2024-56916 can allow an attacker to manipulate user input, potentially leading to unauthorized actions or data exposure for the victim.