Show filters
89 Total Results
Displaying 41-50 of 89
Sort by:
Attacker Value
Unknown

CVE-2022-29429

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.
Attacker Value
Unknown

CVE-2022-23064

Disclosure Date: May 01, 2022 (last updated February 23, 2025)
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.
0
Attacker Value
Unknown

CVE-2022-1511

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Attacker Value
Unknown

CVE-2022-1445

Disclosure Date: April 24, 2022 (last updated February 23, 2025)
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
Attacker Value
Unknown

CVE-2022-1380

Disclosure Date: April 16, 2022 (last updated February 23, 2025)
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
Attacker Value
Unknown

CVE-2022-1155

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
Attacker Value
Unknown

CVE-2021-25010

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2022-0622

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
Attacker Value
Unknown

CVE-2022-0611

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
Attacker Value
Unknown

CVE-2022-0579

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.