PT-2022-4504 · Snipe-It · Snipe-It

Snipe

·

Published

2022-08-29

·

Updated

2022-09-01

·

CVE-2022-3035

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions snipe-it versions prior to 6.0.11
Description The issue is related to a Cross-site Scripting (XSS) - Stored vulnerability. It exists due to inadequate protection of the web page structure, allowing a remote attacker to conduct an inter-site scripting attack.
Recommendations For versions prior to 6.0.11, update to version 6.0.11 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable web pages until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-05371
CVE-2022-3035
GHSA-RFF2-VQM3-JPV5

Affected Products

Snipe-It