CVE-2024-47226

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*

History

30 Jun 2025, 14:50

Type Values Removed Values Added
CPE cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*
First Time Netbox netbox
Netbox
References () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - () https://github.com/netbox-community/netbox/releases/tag/v4.1.0 - Release Notes
References () https://github.com/tu3n4nh/netbox/issues/1 - () https://github.com/tu3n4nh/netbox/issues/1 - Exploit, Issue Tracking

10 Feb 2025, 22:15

Type Values Removed Values Added
Summary (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. (en) A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

Information

Published : 2024-09-22 02:15

Updated : 2025-06-30 14:50


NVD link : CVE-2024-47226

Mitre link : CVE-2024-47226

CVE.ORG link : CVE-2024-47226


JSON object : View

Products Affected

netbox

  • netbox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')