vendor:
SnipeIT
by:
Shahzaib Ali Khan
4.1
CVSS
MEDIUM
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: SnipeIT
Affected Version From: 6.2.2001
Affected Version To: 6.2.2001
Patch Exists: NO
Related CWE: CVE-2023-5452
CPE: a:snipeit:snipeit:6.2.1
Platforms Tested: Windows 11 22H2, Ubuntu 20.04
2023
SnipeIT 6.2.1 – Stored Cross Site Scripting
SnipeIT version 6.2.1 is vulnerable to stored cross-site scripting (XSS) due to a flaw that enables malicious actors to run JavaScript commands. The vulnerability lies in the location endpoint.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs, encode output, and implement proper input validation mechanisms.