PT-2024-34522 · Snipe-It · Snipe-It
Avihay Eldad
+1
·
Published
2024-11-12
·
Updated
2024-11-19
·
CVE-2024-51094
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Snipe-IT version 7.0.13 build 15514
Description:
The issue allows a low-privileged attacker to modify their profile name and inject a malicious payload into the
Name field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.Recommendations:
For Snipe-IT version 7.0.13 build 15514, as a temporary workaround, consider restricting access to the
Name field in the profile management section to prevent malicious payload injection until a patch is available. Additionally, restrict the export of data as CSV files from the People Management page to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It