vendor:
SnipeIT
by:
Shahzaib Ali Khan
4.1
CVSS
MEDIUM
Stored Cross Site Scripting
79
CWE
Product Name: SnipeIT
Affected Version From: 6.2.2001
Affected Version To: 6.2.2001
Patch Exists: NO
Related CWE: CVE-2023-5452
CPE: a:snipeit:snipeit:6.2.1
Platforms Tested: Windows 11 22H2, Ubuntu 20.04
2023
SnipeIT 6.2.1 – Stored Cross Site Scripting
SnipeIT version 6.2.1 is prone to a stored cross-site scripting (XSS) vulnerability, which could allow attackers to execute arbitrary JavaScript code. The vulnerability exists in the location endpoint.
Mitigation:
To mitigate this issue, it is recommended to sanitize user inputs and encode special characters before displaying them on the web page.