CVE-2025-57543: XSS
Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57543?
CVE-2025-57543 is classified as a medium severity vulnerability due to its potential for user interface attacks through Cross-Site Scripting.
How do I fix CVE-2025-57543?
To fix CVE-2025-57543, update NetBox to version 4.3.6 or later where the vulnerability has been patched.
What types of attacks can CVE-2025-57543 lead to?
CVE-2025-57543 can lead to user interface redress attacks and potentially escalate to Cross-Site Scripting in certain contexts.
In which version of NetBox is CVE-2025-57543 present?
CVE-2025-57543 is present in NetBox version 4.3.5.
Who is affected by CVE-2025-57543?
Users of NetBox version 4.3.5 are affected by CVE-2025-57543, as the vulnerability exists in the 'comment' field on object forms.