CVE-2024-40731

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jul 9, 2024
Updated: Jul 11, 2024
CWE ID 79

Summary

CVE-2024-40731 is a newly discovered cross-site scripting (XSS) vulnerability affecting netbox version 4.0.3. This issue enables attackers to inject arbitrary web scripts or HTMLcode into the Name parameter of the /dcim/rear-ports/{id}/edit/ endpoint. Successful exploitation could result in unintended execution of malicious code on users' browsers, potentially leading to session hijacking or data theft. Netbox users are strongly advised to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share