-
Notifications
You must be signed in to change notification settings - Fork 2.9k
Closed
Labels
status: acceptedThis issue has been accepted for implementationThis issue has been accepted for implementationtype: bugA confirmed report of unexpected behavior in the applicationA confirmed report of unexpected behavior in the application
Description
NetBox version
v3.0.9
Python version
3.8
Steps to Reproduce
- installed Netbox from docker
https://hub.docker.com/r/netboxcommunity/netbox/ - use any input that accepts markdown
- submit this payload :
[37qpypz37qpypz37qpypz37qpypz37qpypz]
37qpypz37qpypz37qpypz37qpypz37qpypz]: javascript:alert(1)
- when the submiting the for click the link and the xss will fire up
Expected Behavior
the payload is dangerous and allowing XSS attack
Observed Behavior
executing javascript in admin dashboard
Metadata
Metadata
Assignees
Labels
status: acceptedThis issue has been accepted for implementationThis issue has been accepted for implementationtype: bugA confirmed report of unexpected behavior in the applicationA confirmed report of unexpected behavior in the application