CVE Feed

    Dashboard / CVE / CVE-2024-47226

    CVE-2024-47226

    A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

    Published:Sep 22, 2024
    Last Modified:Jun 30, 2025
    EPS:Sep 22, 2024
    EPSS Score:0.00023
    CVSS Score:5.4

    Affected Products

    Vendor
    Lenel
    Product
    Netbox
    Vendor
    Netbox
    Product
    Netbox

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High