Vulnerability Description
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | 7.0.13 |
Related Weaknesses (CWE)
References
- https://gist.githubusercontent.com/Tommywarren/ca70f1c43f4ec34dc19cd13459535780/Third Party Advisory
FAQ
What is CVE-2024-51093?
CVE-2024-51093 is a vulnerability with a CVSS score of 8.7 (HIGH). Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the paylo...
How severe is CVE-2024-51093?
CVE-2024-51093 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51093?
Check the references section above for vendor advisories and patch information. Affected products include: Snipeitapp Snipe-It.