Описание
Snipe-IT allows stored XSS via the Locations "Country" field
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
Пакеты
Наименование
snipe/snipe-it
composer
Затронутые версииВерсия исправления
< 8.3.4
8.3.4
Связанные уязвимости
CVSS3: 5.4
nvd
2 месяца назад
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
CVSS3: 5.4
debian
2 месяца назад
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" fi ...