CVE-2024-56918: XSS
In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56918?
CVE-2024-56918 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks affecting the login page.
How do I fix CVE-2024-56918?
To mitigate CVE-2024-56918, it is advised to upgrade to the latest version of Netbox Community that resolves this XSS vulnerability.
Who is affected by CVE-2024-56918?
CVE-2024-56918 affects users of Netbox Community version 4.1.7 and earlier who access the login page.
What type of attack is possible with CVE-2024-56918?
CVE-2024-56918 enables privileged authenticated attackers to carry out cross-site scripting (XSS) attacks to exfiltrate user input from the login form.
Is CVE-2024-56918 remote exploitable?
CVE-2024-56918 is not remotely exploitable as it requires an authenticated attacker to exploit the vulnerability.