Количество 3
Количество 3
CVE-2026-55464
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.
CVE-2026-55464
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, Com ...
GHSA-r52f-r9v5-66xr
Snipe-IT vulnerable to stored XSS via Markdown custom field
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55464 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-55464 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, Com ... | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-r52f-r9v5-66xr Snipe-IT vulnerable to stored XSS via Markdown custom field | CVSS3: 5.4 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу