CVE-2024-56916

I

n Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration History version or attempts to Add a new version, the XSS payload will trigger.

Configurations

Configuration 1 (hide)

cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*

History

30 Jun 2025, 14:43

Type Values Removed Values Added
CPE cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*
First Time Netbox netbox
Netbox
References () https://github.com/netbox-community/netbox/releases/tag/v4.1.7 - () https://github.com/netbox-community/netbox/releases/tag/v4.1.7 - Release Notes
References () https://github.com/noxlumens/Vulnerability-Research/tree/main/CVE-2024-56916 - () https://github.com/noxlumens/Vulnerability-Research/tree/main/CVE-2024-56916 - Third Party Advisory, Exploit
References () https://www.youtube.com/watch?v=GC8-PUlu2i8 - () https://www.youtube.com/watch?v=GC8-PUlu2i8 - Exploit

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) En Netbox Community 4.1.7, una vez autenticado, la opción "Historial de Configuración > Agregar" es vulnerable a ataques de Cross-Site Scripting (XSS) debido a que el campo "valor actual" representa el HTML proporcionado por el usuario. Un atacante autenticado puede aprovechar esto para agregar JavaScript malicioso al campo "Cualquier banner". Al editar una versión del Historial de Configuración o intentar agregar una nueva versión, se activa el payload XSS.

24 Jun 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

24 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 18:15

Updated : 2025-06-30 14:43


NVD link : CVE-2024-56916

Mitre link : CVE-2024-56916

CVE.ORG link : CVE-2024-56916


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')