Loading HuntDB...

GHSA-hpx4-xjp7-m4vr

GitHub Security Advisory

Stored cross-site scripting in Snipe-IT

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Snipe-IT prior to version 5.4.3 is vulnerable to stored cross-site scripting because the input to the `checked_out_to` parameter is not escaped. The vulnerability is capable of stealing a user's cookie.

Affected Packages

Packagist snipe/snipe-it
Affected versions: 0 (fixed in 5.4.3)

Related CVEs

Key Information

GHSA ID
GHSA-hpx4-xjp7-m4vr
Published
April 25, 2022 12:00 AM
Last Modified
May 18, 2022 8:01 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
snipe/snipe-it
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.