High severity8.7NVD Advisory· Published Nov 12, 2024· Updated Jun 17, 2026
CVE-2024-51093
CVE-2024-51093
Description
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | <= 7.0.13 | — |
Affected products
3- cpe:2.3:a:snipeitapp:snipe-it:7.0.13:*:*:*:*:*:*:*
- Snipe-IT/Snipe-ITdescription
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.