Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4wj-v9vp-683h

Опубликовано: 03 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.4

Описание

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 15%
0.00243
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
5 месяцев назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

CVSS3: 6.4
debian
5 месяцев назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerabilit ...

EPSS

Процентиль: 15%
0.00243
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79