PT-2026-32381 · Snipe-It · Snipe-It

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2025-63743

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions 8.3.0 through 8.3.1
Description A Cross-Site Scripting issue allows an authenticated attacker with minimum privileges to inject arbitrary JavaScript code through the Name and Surname fields. This code executes when a user with appropriate permissions views the modified profile or the Activity Report. This occurs only if the Display Name of the profile is not configured.
Recommendations Update versions 8.3.0 through 8.3.1 to version 8.3.2. As a temporary workaround, restrict the use of the Name and Surname fields to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63743

Affected Products

Snipe-It