snipe
24 exploits
Active since Oct 2021
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVSS 7.1
Snipe-IT: XSS vulnerability in component notes
CVSS 4.8
Snipe-IT: Privilege Escalation via API Permissions Assignment
CVSS 8.8
Snipe-IT: Open redirect vulnerability
CVSS 5.9
snipe-it < 8.4.1 - Remote Code Execution via UploadedFilesController
CVSS 9.8
Snipe-IT 8.3.0-8.3.1 - Authenticated Stored Cross-Site Scripting via Name and Surname Fields
CVSS 5.4
snipe-it < 5.3.0 - Cross-Site Request Forgery
CVSS 8.8
snipe-it < 5.3.0 - Stored Cross-Site Scripting
CVSS 6.1
snipe-it < 5.3.0 - Stored Cross-Site Scripting
CVSS 5.4
snipe-it < 5.3.1 - Cross-Site Request Forgery
CVSS 4.3
snipe-it < 5.3.2 - Stored Cross-Site Scripting
CVSS 5.4
snipe-it < 5.3.5 - Stored Cross-Site Scripting
CVSS 6.1
snipe-it < 5.3.6 - Cross-Site Request Forgery
CVSS 8.8
Packagist snipe/snipe-it <5.3.9 - Info Disclosure
CVSS 5.3
Packagist snipe/snipe-it <5.3.9 - Info Disclosure
CVSS 6.5
Packagist snipe/snipe-it <5.3.11 - Info Disclosure
CVSS 6.3
Packagist snipe/snipe-it <5.3.11 - Info Disclosure
CVSS 5.3
GitHub snipe-it <5.3.10 - Info Disclosure
CVSS 7.4
GitHub snipe/snipe-it <6.0.10 - Info Disclosure
CVSS 8.0
GitHub repository snipe/snipe-it <6.0.11 - XSS
CVSS 4.8
Snipe-IT < 6.0.10 - Improper Authentication
CVSS 4.3
snipe-it < 6.2.2 - Stored Cross-Site Scripting
CVSS 5.4
Snipe-IT < 6.2.3 - Cross-Site Request Forgery
CVSS 8.8
snipe-it <6.4.1 - Privilege Escalation
CVSS 7.6