Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25264

Опубликовано: 03 фев. 2026
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 8%
0.0003
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
debian
4 дня назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerabilit ...

CVSS3: 6.4
github
4 дня назад

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

EPSS

Процентиль: 8%
0.0003
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79