Netbox Community
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*, +1 more
- 4.1.7
A cross-site scripting (XSS) vulnerability has been identified in the login page of NetBox Community version 4.1.7. This issue allows a privileged, authenticated attacker to exfiltrate user input from the login form.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, log into a NetBox Community 4.1.7 instance as a privileged user. Navigate to the login page and inject a script into the login form. Once the script is submitted, it will be executed, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.