Snipeitapp

Snipe-it

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 20.11.2025 00:00:00
  • Zuletzt bearbeitet 26.11.2025 16:15:50

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin i...

  • EPSS 0.54%
  • Veröffentlicht 05.11.2025 00:00:00
  • Zuletzt bearbeitet 01.12.2025 16:15:56

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.

  • EPSS 0.35%
  • Veröffentlicht 19.09.2025 00:00:00
  • Zuletzt bearbeitet 23.09.2025 16:57:34

Snipe-IT before 8.1.18 allows unsafe deserialization.

  • EPSS 0.24%
  • Veröffentlicht 19.09.2025 00:00:00
  • Zuletzt bearbeitet 23.09.2025 16:57:45

Snipe-IT before 8.1.18 allows XSS.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 02.05.2025 00:00:00
  • Zuletzt bearbeitet 03.06.2025 14:44:17

Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • EPSS 0.43%
  • Veröffentlicht 12.11.2024 21:15:14
  • Zuletzt bearbeitet 22.05.2025 17:28:00

An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV f...

  • EPSS 0.4%
  • Veröffentlicht 12.11.2024 21:15:14
  • Zuletzt bearbeitet 21.11.2024 18:15:11

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin ...

Exploit
  • EPSS 0.96%
  • Veröffentlicht 11.10.2024 13:15:16
  • Zuletzt bearbeitet 22.05.2025 17:56:50

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

  • EPSS 0.41%
  • Veröffentlicht 14.06.2024 10:15:10
  • Zuletzt bearbeitet 07.03.2025 14:55:48

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 11.10.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 08:41:54

Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.