Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-55481

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snipe-ititppackage

EPSS

Процентиль: 15%
0.00236
Низкий

Связанные уязвимости

CVSS3: 4.8
nvd
2 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.

github
26 дней назад

Snipe-IT has CSS Injection via `header_color` Setting

EPSS

Процентиль: 15%
0.00236
Низкий