Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hw9x-8m75-4vjq | Cross Site Scripting vulnerability in Snipe-IT |
Thu, 21 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Mon, 18 Nov 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Snipeitapp
Snipeitapp snipe-it |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:7.0.13:*:*:*:*:*:*:* | |
| Vendors & Products |
Snipeitapp
Snipeitapp snipe-it |
|
| Metrics |
cvssV3_1
|
Thu, 14 Nov 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Snipe-IT v.7.0.13 allows a remote attacker to escalate privileges via an unknown part of the file /users/{{user-id}}/#files. | Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system. |
Tue, 12 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Snipe-IT v.7.0.13 allows a remote attacker to escalate privileges via an unknown part of the file /users/{{user-id}}/#files. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-21T18:10:21.900Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-51093
Updated: 2024-11-21T18:09:59.363Z
Status : Modified
Published: 2024-11-12T21:15:14.027
Modified: 2024-11-21T18:15:11.043
Link: CVE-2024-51093
No data.
OpenCVE Enrichment
No data.
Github GHSA