Vulnerabilities
CVE-2024-5685
HIGHUsers with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
CVE-2023-5511
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
CVE-2023-5452
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
CVE-2022-3173
MEDIUMImproper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
CVE-2022-3035
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
CVE-2022-2997
MEDIUMSession Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
CVE-2022-23064
HIGHIn Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.
CVE-2022-1511
MEDIUMMissing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
CVE-2022-1445
CRITICALStored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
CVE-2022-1380
CRITICALStored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
CVE-2022-1155
HIGHOld sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
CVE-2022-0622
MEDIUMGeneration of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0611
MEDIUMMissing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0579
MEDIUMMissing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
CVE-2022-0569
MEDIUMObservable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
CVE-2022-0178
MEDIUMMissing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVE-2022-0179
MEDIUMsnipe-it is vulnerable to Missing Authorization
CVE-2021-4130
MEDIUMsnipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4108
MEDIUMsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4089
MEDIUMsnipe-it is vulnerable to Improper Access Control
CVE-2021-4075
LOWsnipe-it is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2021-4018
MEDIUMsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3961
HIGHsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3931
MEDIUMsnipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3938
LOWsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3879
MEDIUMsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3863
MEDIUMsnipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3858
MEDIUMsnipe-it is vulnerable to Cross-Site Request Forgery (CSRF)