PT-2020-10894 · Netbox · Netbox
Cloneassassin
·
Published
2020-12-31
·
Updated
2024-02-02
·
CVE-2019-25011
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NetBox versions 2.6.2 and earlier
Description
The issue allows an authenticated user to conduct a cross-site scripting (XSS) attack against an admin via a GFM-rendered field. This can be demonstrated by the "/dcim/sites/add/" endpoint, specifically through comments.
Recommendations
For versions 2.6.2 and earlier, consider disabling GFM-rendered fields until a patch is available. Restrict access to the "/dcim/sites/add/" endpoint to minimize the risk of exploitation. Avoid using comments in the affected endpoint until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netbox