vendor:
Snipe-IT
by:
Metin Yunus Kandemir (kandemir)
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Snipe-IT
Affected Version From: 4.7.5
Affected Version To: 4.7.5
Patch Exists: NO
Related CWE: N/A
CPE: a:snipeitapp:snipe-it:4.7.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xampp for Windows
2020
Snipe-IT Open Source Asset Management 4.7.5 – Persistent Cross-Site Scripting
Snipe-IT v4.7.5 has persistent cross-site scripting vulnerability via uploading svg file in accessories section. A malicious authorized user could potentially upload an SVG with a javascript payload.
Mitigation:
Restrict access to the application and ensure that only authorized users can upload files.