Vulnerability Description
NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netbox | Netbox | >= 2.11.0, <= 3.7.8 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-69848?
CVE-2025-69848 is a vulnerability with a CVSS score of 5.4 (MEDIUM). NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the Protec...
How severe is CVE-2025-69848?
CVE-2025-69848 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69848?
Check the references section above for vendor advisories and patch information. Affected products include: Netbox Netbox.