PT-2024-34521 · Snipe-It · Snipe-It

Avihay Eldad

+1

·

Published

2024-11-12

·

Updated

2024-11-18

·

CVE-2024-51093

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Snipe-IT version 7.0.13
Description: A Stored Cross-Site Scripting (XSS) issue allows an attacker to upload a malicious XML file containing JavaScript code, potentially leading to privilege escalation when the payload is executed. This could grant the attacker super admin permissions within the Snipe-IT system. The vulnerability can be exploited via an unknown part of the file /users/{{user-id}}/#files, allowing a remote attacker to escalate privileges.
Recommendations: For Snipe-IT version 7.0.13, consider disabling the file upload feature or restricting access to the /users/{{user-id}}/#files endpoint until a patch is available. Avoid using the user-id variable in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51093
GHSA-HW9X-8M75-4VJQ

Affected Products

Snipe-It