VYPR
Medium severity5.4NVD Advisory· Published Sep 22, 2024· Updated Jun 17, 2026

CVE-2024-47226

CVE-2024-47226

Description

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this as not a vulnerability. It is argued that the configuration revision banner feature is meant to contain unsanitized HTML in order to display notifications to users. Since these fields are intended to display unsanitized HTML, this is working as intended.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • NetBox/NetBox2 versions
    cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:netbox:netbox:4.1.0:-:*:*:*:*:*:*
    • (no CPE)range: <4.1.0
  • NetBox/NetBoxdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.