Description
Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Metin Yunus Kandemir (kandemir)
References
www.exploit-db.com/exploits/47756 (ExploitDB-47756)
snipeitapp.com/ (Official Vendor Homepage)
github.com/snipe/snipe-it/releases/tag/v4.7.5 (Snipe-IT Software Release v4.7.5)
www.vulncheck.com/...agement-persistent-cross-site-scripting (VulnCheck Advisory: Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting)