Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-55481

3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-55481

3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, def ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-w7qw-5wfv-gwx9

26 дней назад

Snipe-IT has CSS Injection via `header_color` Setting

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55481

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.

CVSS3: 4.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55481

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, def ...

CVSS3: 4.8
0%
Низкий
3 месяца назад
github логотип
GHSA-w7qw-5wfv-gwx9

Snipe-IT has CSS Injection via `header_color` Setting

0%
Низкий
26 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.