7.1
CVE-2026-44833
- EPSS 0.16%
- Veröffentlicht 26.05.2026 19:30:48
- Zuletzt bearbeitet 26.05.2026 20:38:06
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Snipe-IT: Open redirect vulnerability
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snipeitapp ≫ Snipe-it Version < 8.4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 2.8 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
|
| security-advisories@github.com | 5.9 | 1.7 | 3.7 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://github.com/grokability/snipe-it/security/advisories/GHSA-mghp-5cq4-v6mg
https://github.com/grokability/snipe-it/commit/e37649212861a337e68a624e589c3540b7a82373