CVE-2024-0948 | NetBox up to 3.7.0 Home Page Configuration /core/config-revisions cross site scripting (Duplicate CVE-2024-47226 / Replaces VDB-278259)
A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of the file /core/config-revisions of the component Home Page Configuration. The manipulation with the input <<h1 onload=alert(1)>>test</h1> leads to cross site scripting.
The identification of this vulnerability is CVE-2024-0948. The attack may be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment. The vendor was contacted early about this disclosure but did not respond in any way.
Our investigation indicates that a second CVE-2024-47226 was assigned to this entry.