Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25264

Опубликовано: 03 фев. 2026
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 15%
0.00243
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
debian
5 месяцев назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerabilit ...

CVSS3: 6.4
github
5 месяцев назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 15%
0.00243
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79