Loading HuntDB...

Vulnerabilities

CVE-2024-5685

HIGH

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

Published Jun 14, 2024

CVE-2023-5511

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.

Published Oct 11, 2023

CVE-2023-5452

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

Published Oct 06, 2023

CVE-2022-3173

MEDIUM

Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

Published Sep 17, 2022

CVE-2022-3035

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

Published Aug 29, 2022

CVE-2022-2997

MEDIUM

Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

Published Aug 25, 2022

CVE-2022-23064

HIGH

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

Published May 02, 2022

CVE-2022-1511

MEDIUM

Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

Published Apr 28, 2022

CVE-2022-1445

CRITICAL

Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

Published Apr 24, 2022

CVE-2022-1380

CRITICAL

Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.

Published Apr 16, 2022

CVE-2022-1155

HIGH

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

Published Mar 30, 2022

CVE-2022-0622

MEDIUM

Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

Published Feb 17, 2022

CVE-2022-0611

MEDIUM

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

Published Feb 15, 2022

CVE-2022-0579

MEDIUM

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

Published Feb 14, 2022

CVE-2022-0569

MEDIUM

Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.

Published Feb 12, 2022

CVE-2022-0178

MEDIUM

Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

Published Jan 13, 2022

CVE-2022-0179

MEDIUM

snipe-it is vulnerable to Missing Authorization

Published Jan 12, 2022

CVE-2021-4130

MEDIUM

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Published Dec 18, 2021

CVE-2021-4108

MEDIUM

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 14, 2021

CVE-2021-4089

MEDIUM

snipe-it is vulnerable to Improper Access Control

Published Dec 10, 2021

CVE-2021-4075

LOW

snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 06, 2021

CVE-2021-4018

MEDIUM

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 01, 2021

CVE-2021-3961

HIGH

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Nov 19, 2021

CVE-2021-3931

MEDIUM

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Published Nov 13, 2021

CVE-2021-3938

LOW

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Nov 13, 2021

CVE-2021-3879

MEDIUM

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Oct 19, 2021

CVE-2021-3863

MEDIUM

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Oct 19, 2021

CVE-2021-3858

MEDIUM

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Published Oct 19, 2021