VYPR
High severityNVD Advisory· Published Nov 12, 2024· Updated Nov 21, 2024

CVE-2024-51093

CVE-2024-51093

Description

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Snipe-IT v7.0.13 via malicious XML upload leads to privilege escalation to super admin.

Vulnerability

Description A Stored Cross-Site Scripting (XSS) vulnerability exists in Snipe-IT version 7.0.13 [1]. The application fails to properly sanitize XML file uploads, allowing an attacker to embed malicious JavaScript code within an XML file [3]. When the file is uploaded and subsequently viewed by an authorized user, the script executes in the browser context.

Exploitation

To exploit this vulnerability, an attacker must upload a specially crafted XML file containing JavaScript payloads [3]. The attack can be performed by any authenticated user with file upload privileges, typically through asset import functionality. No special network position is required; the attacker only needs access to the Snipe-IT web interface.

Impact

Successful exploitation results in privilege escalation, granting the attacker super admin permissions within the Snipe-IT system [1]. This gives full control over all assets, licenses, users, and configuration, potentially leading to data breaches, system compromise, and further lateral movement within the network.

Mitigation

The vendor has been notified and a fix is expected in a future release [2]. Users are strongly advised to update Snipe-IT to the latest patched version as soon as it becomes available. In the interim, restrict XML file upload capabilities and review uploaded files manually. The vulnerability has been assigned CWE-79 and CVE-2024-51093 [3].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
snipe/snipe-itPackagist
<= 7.0.13

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.