CVE-2024-34707
CVE-2024-34707 in Nautobot allows admins to inject arbitrary HTML. This can lead to cross-site scripting (XSS) attacks, potentially compromising user security. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, highlighting a moderate risk. An admin user can modify banner settings to inject malicious HTML code. This injected code executes when other users view those banners. This stored XSS vulnerability could allow an attacker to steal credentials or perform actions on behalf of unsuspecting users. Update to Nautobot versions 1.6.22 or 2.2.4 to mitigate this security flaw.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.