Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4wj-v9vp-683h

Опубликовано: 03 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.4

Описание

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 8%
0.0003
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
4 дня назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

CVSS3: 6.4
debian
4 дня назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerabilit ...

EPSS

Процентиль: 8%
0.0003
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79