Vulnerabilities
Vulnerable Software
Snipeitapp:  >> Snipe-It  Security Vulnerabilities
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
CVSS Score
5.9
EPSS Score
0.001
Published
2022-08-29
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
CVSS Score
4.6
EPSS Score
0.009
Published
2022-08-25
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
CVSS Score
4.8
EPSS Score
0.05
Published
2022-07-07
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
CVSS Score
4.8
EPSS Score
0.004
Published
2022-07-07
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-05-02
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-04-28
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
CVSS Score
9.0
EPSS Score
0.003
Published
2022-04-24
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
CVSS Score
9.1
EPSS Score
0.002
Published
2022-04-16
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
CVSS Score
7.4
EPSS Score
0.002
Published
2022-03-30
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVSS Score
5.3
EPSS Score
0.001
Published
2022-02-17


Contact Us

Shodan ® - All rights reserved