Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown

CVE-2022-32060

Disclosure Date: July 07, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
Attacker Value
Unknown

CVE-2022-23064

Disclosure Date: May 01, 2022 (last updated February 23, 2025)
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.
0
Attacker Value
Unknown

CVE-2022-1511

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Attacker Value
Unknown

CVE-2022-1445

Disclosure Date: April 24, 2022 (last updated February 23, 2025)
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
Attacker Value
Unknown

CVE-2022-1380

Disclosure Date: April 16, 2022 (last updated February 23, 2025)
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
Attacker Value
Unknown

CVE-2022-1155

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
Attacker Value
Unknown

CVE-2022-0622

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
Attacker Value
Unknown

CVE-2022-0611

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
Attacker Value
Unknown

CVE-2022-0579

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
Attacker Value
Unknown

CVE-2022-0569

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.