www.vulncheck.com
Snipe-IT Vulnerabilities: RCE and CSS Injection Risks Identified
Article Content
Two critical vulnerabilities have been discovered in Snipe-IT versions prior to 8.7.0. The first, a remote code execution (RCE) vulnerability, is due to improper handling of backup restores, categorized as CWE-78. The second vulnerability allows CSS injection through custom CSS, classified as CWE-79. These vulnerabilities affect all versions before 8.7.0, potentially allowing attackers to execute arbitrary code or inject malicious scripts. The vulnerabilities have been documented in GitHub Security Advisories (GHSA-x53f-48vj-c5fc and GHSA-pvcw-mp8q-mj39). Users are urged to upgrade to version 8.7.0 or later to mitigate these risks. As of now, there is no indication of active exploitation in the wild, but the vulnerabilities are significant enough to warrant immediate attention.
Key Points: • Two vulnerabilities in Snipe-IT before version 8.7.0: RCE and CSS injection. • RCE vulnerability allows arbitrary code execution via backup restore. • CSS injection vulnerability enables script injection through custom CSS.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.