CVE-2024-40730

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jul 9, 2024
Updated: Jul 11, 2024
CWE ID 79

Summary

CVE-2024-40730 is a newly discovered cross-site scripting (XSS) vulnerability affecting version 4.0.3 of the network management system, netbox. This issue allows malicious actors to inject arbitrary web scripts or HTML into the Name parameter of the /dcim/interfaces/{id}/edit/ endpoint. Successful exploitation of this vulnerability could lead to unintended execution of code in the context of the affected user, potentially resulting in data theft or other malicious activities. Netbox users are strongly encouraged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share