CyberRota Analysis
AI-GeneratedSnipe-IT versions prior to 8.7.0 are vulnerable to a stored cross-site scripting (XSS) attack, where a user with the customfields.create permission can inject malicious markup into the CustomField.name. This vulnerability allows an attacker to execute arbitrary scripts in the context of another user's session, potentially exposing sensitive data and enabling unauthorized actions, including privilege escalation. Organizations using affected versions should prioritize upgrading to version 8.7.0 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)