PT-2026-32381 · Snipe-It · Snipe-It
Published
2026-04-13
·
Updated
2026-04-13
·
CVE-2025-63743
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions 8.3.0 through 8.3.1
Description
A Cross-Site Scripting issue allows an authenticated attacker with minimum privileges to inject arbitrary JavaScript code through the
Name and Surname fields. This code executes when a user with appropriate permissions views the modified profile or the Activity Report. This occurs only if the Display Name of the profile is not configured.Recommendations
Update versions 8.3.0 through 8.3.1 to version 8.3.2.
As a temporary workaround, restrict the use of the
Name and Surname fields to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It