CVE-2024-32979
CVE-2024-32979 allows for Reflected XSS attacks in Nautobot. This vulnerability arises from improper handling of user-provided query parameters, potentially enabling malicious actors to inject scripts via crafted URLs. All filterable object-list views in Nautobot are susceptible. With an SVRS of 30, while not critical, this vulnerability still presents a risk of unauthorized script execution within a user's browser. Successful exploitation can lead to session hijacking, data theft, or defacement of the web interface. Nautobot versions 1.6.20 and 2.2.3 address this security flaw. Organizations using earlier versions should upgrade immediately to mitigate potential cybersecurity threats.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.