Both reflexive and stored XSS flaw through object creation #851

Closed
opened 2025-12-29 16:26:21 +01:00 by adam · 0 comments
Owner

Originally created by @asteinhauser on GitHub (Apr 10, 2017).

screenrecord.zip

Python version 2.7
Netbox version v1.9.5 - 2017-04-06

Bug reproduction is in the attachment. Just add something like VLAN group and write JavaScript code into the name. It creates both reflective XSS and later stored XSS on the main page.

Originally created by @asteinhauser on GitHub (Apr 10, 2017). [screenrecord.zip](https://github.com/digitalocean/netbox/files/910290/screenrecord.zip) Python version 2.7 Netbox version v1.9.5 - 2017-04-06 Bug reproduction is in the attachment. Just add something like VLAN group and write JavaScript code into the name. It creates both reflective XSS and later stored XSS on the main page.
adam added the type: bug label 2025-12-29 16:26:21 +01:00
adam closed this issue 2025-12-29 16:26:21 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#851