Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-34565: Stored Cross Site Scripting Vulnerability in "Create Wireless LAN Groups" function in Netbox 3.5.1 · Issue #1 · grayfullbuster0804/netbox

Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the “Create Wireless LAN Groups” function.

CVE
#xss#vulnerability#auth

****Description****

An authenticated malicious user can take advantage of a Stored XSS vulnerability in “Wireless LAN” function in the “GROUP” feature.

Proof of Concept
Step 1: Go to /wireless/wireless-lan-groups/, click “Add” and insert payload “<img src=x onerror=alert(‘XSS’);>” in “Name” field.

Step 2: Go to dev/wireless/wireless-lans/, Select one element and click "Edit Selected", after select “Group”

**Step 3: Script excuted

Impact
If an attacker can control a script that is executed in the victim’s browser, then they can typically fully compromise that user.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907