CVE-2024-0948 Overview
CVE-2024-0948 is a disputed cross-site scripting (XSS) vulnerability reported against NetBox versions up to 3.7.0. The issue affects the /core/config-revisions endpoint within the Home Page Configuration component. An attacker can allegedly inject HTML payloads such as <h1 onload=alert(1)>test</h1> to trigger script execution in a victim's browser. The report is marked as disputed because the vendor was contacted but did not respond, and the real existence of the flaw remains in doubt. The vulnerability is tracked under VulDB identifier VDB-252191 and classified under CWE-79.
Critical Impact
A successful XSS attack against an authenticated NetBox administrator could allow session hijacking, credential theft, or unauthorized changes to network inventory data.
Affected Products
- NetBox versions up to and including 3.7.0
- The Home Page Configuration component at /core/config-revisions
- Deployments where administrative users interact with untrusted configuration input
Discovery Timeline
- 2024-01-26 - CVE-2024-0948 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-0948
Vulnerability Analysis
The report describes a stored or reflected XSS condition in NetBox's Home Page Configuration feature. According to the disclosure, the /core/config-revisions endpoint processes user-supplied input without sufficient output encoding. Submitting HTML markup that includes event handlers such as onload reportedly causes the browser to execute attacker-controlled JavaScript.
The report is publicly disputed. The vendor did not confirm the finding, and independent verification is limited to the VulDB submission referenced as VulDB #252191. Organizations should validate the presence of the flaw in their own deployments before treating it as confirmed.
Root Cause
The reported root cause is improper neutralization of user input during web page generation, categorized as [CWE-79]. The affected view within the Home Page Configuration component appears to render input containing HTML tags and inline event handlers without escaping angle brackets or attribute values.
Attack Vector
Exploitation requires an attacker to deliver a crafted payload to a target user who then interacts with the vulnerable endpoint. Because the attack requires user interaction and operates across a security scope boundary, an attacker typically must lure an authenticated NetBox user, such as an administrator, into visiting or submitting the malicious content.
No verified public exploit code or proof-of-concept beyond the payload string <h1 onload=alert(1)>test</h1> is documented in the enriched data. See the referenced VulDB entry for the original submission details.
Detection Methods for CVE-2024-0948
Indicators of Compromise
- HTTP requests to /core/config-revisions containing HTML tags, event handler attributes such as onload, onerror, or onclick, or <script> fragments
- Configuration revision entries that persist unexpected HTML markup or JavaScript payloads
- Browser console errors or unexpected script execution when NetBox administrators load the home page
Detection Strategies
- Inspect web server and application logs for requests to the Home Page Configuration endpoint that include encoded or raw angle brackets
- Review NetBox audit trails for configuration revisions submitted by unexpected accounts or containing markup rather than plain text
- Deploy web application firewall rules that flag reflected HTML payloads targeting NetBox administrative paths
Monitoring Recommendations
- Alert on anomalous administrative session activity following visits to /core/config-revisions
- Monitor outbound requests from administrator browsers that could indicate session token exfiltration
- Track changes to NetBox configuration objects and correlate them with user identity and source IP
How to Mitigate CVE-2024-0948
Immediate Actions Required
- Restrict access to the NetBox administrative interface to trusted networks and authenticated users only
- Review recent entries at /core/config-revisions for HTML or JavaScript content and remove any suspicious data
- Enforce a strict Content Security Policy (CSP) that disallows inline scripts and event handlers on NetBox pages
Patch Information
No vendor patch or advisory is referenced in the enriched data for CVE-2024-0948, and the vulnerability remains disputed. Administrators should monitor the official NetBox releases for updates addressing input handling in the Home Page Configuration component and upgrade to the latest stable release as a defensive baseline.
Workarounds
- Limit NetBox administrative privileges to a minimum set of trusted operators to reduce the impact of user-interaction-based XSS
- Front NetBox with a reverse proxy or WAF that strips or blocks HTML tags in request bodies destined for configuration endpoints
- Require administrators to use isolated browser profiles when managing NetBox to reduce the value of any hijacked session
# Example NGINX rule to block obvious HTML payloads to the affected path
location /core/config-revisions {
if ($request_body ~* "<[a-z]+[^>]*on[a-z]+=") {
return 403;
}
proxy_pass http://netbox_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.