Packagist (Composer) package
snipe/snipe-it
pkg:composer/snipe/snipe-it
Vulnerabilities (50)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-4089 | Med | 4.3 | < 5.3.4 | 5.3.4 | Dec 10, 2021 | snipe-it is vulnerable to Improper Access Control | |
| CVE-2021-4075 | Hig | 7.2 | < 6.0.0-GM | 6.0.0-GM | Dec 6, 2021 | snipe-it is vulnerable to Server-Side Request Forgery (SSRF) | |
| CVE-2021-4018 | Med | 5.4 | < 5.3.3 | 5.3.3 | Dec 1, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3961 | Med | 5.4 | < 5.3.2 | 5.3.2 | Nov 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3938 | Med | 5.4 | < 5.4.0 | 5.4.0 | Nov 13, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3931 | Med | 4.3 | <= 5.3.1 | — | Nov 13, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | |
| CVE-2021-3879 | Med | 5.4 | < 5.3.0 | 5.3.0 | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3863 | Med | 6.1 | < 5.3.0 | 5.3.0 | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3858 | Hig | 8.8 | < 5.3.0 | 5.3.0 | Oct 19, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | |
| CVE-2019-10118 | Med | 6.1 | < 4.6.14 | 4.6.14 | Mar 27, 2019 | Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API. |
- affected < 5.3.4fixed 5.3.4
snipe-it is vulnerable to Improper Access Control
- affected < 6.0.0-GMfixed 6.0.0-GM
snipe-it is vulnerable to Server-Side Request Forgery (SSRF)
- affected < 5.3.3fixed 5.3.3
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 5.3.2fixed 5.3.2
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 5.4.0fixed 5.4.0
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected <= 5.3.1
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
- affected < 5.3.0fixed 5.3.0
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 5.3.0fixed 5.3.0
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 5.3.0fixed 5.3.0
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
- affected < 4.6.14fixed 4.6.14
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
Page 3 of 3