PYSEC-2023-141

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pynetbox/PYSEC-2023-141.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2023-141
Withdrawn
2023-08-22T06:23:00Z
Published
2023-08-10T20:15:00Z
Modified
2025-10-09T08:26:23.307985Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

References

Affected packages

PyPI / pynetbox

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
3.*
3.0.0
3.0.1
3.0.2
3.1.0
3.2.0
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.10
3.4.11
4.*
4.0.0rc1
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.1.0
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.2.4
4.2.5
4.3.0
4.3.1
4.3.3
5.*
5.0.1
5.0.3
5.0.4
5.0.5
5.0.7
5.0.8
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.3.0
5.3.1
6.*
6.0.0
6.0.1
6.0.2
6.1.0
6.1.1
6.1.2
6.1.3
6.2.0
6.3.0
6.4.0
6.4.1
6.5.0
6.6.0
6.6.1
6.6.2
7.*
7.0.0
7.0.1
7.1.0
7.2.0
7.3.3
7.3.4
7.4.0
7.4.1
7.5.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pynetbox/PYSEC-2023-141.yaml"