Medium severity5.4NVD Advisory· Published Apr 24, 2022· Updated Jun 17, 2026
CVE-2022-1445
CVE-2022-1445
Description
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | < 5.4.3 | 5.4.3 |
Affected products
3cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*range: <5.4.3
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/snipe/snipe-it/commit/f623d05d0c3487ae24c4f13907e4709484e5bf41nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/f4420149-5236-4051-a458-5d4f1d5b7abdnvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hpx4-xjp7-m4vrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-1445ghsaADVISORY
News mentions
0No linked articles in our index yet.