Stored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
Valid
Reported on
Apr 23rd 2022
Description
The checked_out_to is not escaped, which leads to a XSS problem.
Proof of Concept
1.Login to the demo account
2.Report->Depreciation Report
3.Choose a Asset and goto Assets menu and check it out. new a location which is
'"><img src onerror=alert(3324)>
and check the asset to this location4.Return to Depreciation Report,refresh,a lert will be triggered
'"><img src onerror=alert(3324)>
Impact
The vulnerability is capable of stolen the user Cookie.
Occurrences
We are processing your report and will contact the
snipe/snipe-it
team within 24 hours.
a year ago
mylong modified the report
a year ago
We have contacted a member of the
snipe/snipe-it
team and are waiting to hear back
a year ago
The researcher's credibility has increased: +7
DepreciationReportTransformer.php#L101
has been validated
to join this conversation