A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 30 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netbox
Netbox netbox |
|
CPEs | cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:* | |
Vendors & Products |
Netbox
Netbox netbox |
Mon, 10 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended. |
Mon, 23 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lenel
Lenel netbox |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:lenel:netbox:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lenel
Lenel netbox |
|
Metrics |
cvssV3_1
|
Sun, 22 Sep 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-09-22T00:00:00.000Z
Updated: 2025-02-11T21:43:56.176Z
Reserved: 2024-09-22T00:00:00.000Z
Link: CVE-2024-47226

Updated: 2024-09-23T14:58:04.686Z

Status : Analyzed
Published: 2024-09-22T02:15:02.797
Modified: 2025-06-30T14:50:07.543
Link: CVE-2024-47226

No data.