Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts.
References
| Link | Resource |
|---|---|
| https://gist.github.com/MerttTuran/d94acff59816bfd9492d1a738e89ebb4 | Exploit Third Party Advisory |
| https://gist.github.com/MerttTuran/d94acff59816bfd9492d1a738e89ebb4 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-16 16:16
Updated : 2026-06-17 09:43
NVD link : CVE-2025-57543
Mitre link : CVE-2025-57543
CVE.ORG link : CVE-2025-57543
JSON object : View
Products Affected
netbox
- netbox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
