Medium severity4.8NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026
CVE-2022-32061
CVE-2022-32061
Description
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | <= 6.0.2 | — |
Affected products
3- Snipe-IT/Snipe-ITdescription
- cpe:2.3:a:snipeitapp:snipe-it:6.0.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- grimthereaperteam.medium.com/snipe-it-version-v6-0-2-file-upload-cross-site-scripting-c02e46fa72abnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xwqx-x38c-cw95ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-32061ghsaADVISORY
News mentions
0No linked articles in our index yet.