Filtered by vendor Snipeitapp Subscriptions
Total 33 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-3035 1 Snipeitapp 1 Snipe-it 2024-08-03 4.8 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
CVE-2022-2997 1 Snipeitapp 1 Snipe-it 2024-08-03 8.0 High
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
CVE-2022-1511 1 Snipeitapp 1 Snipe-it 2024-08-03 6.5 Medium
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
CVE-2022-1380 1 Snipeitapp 1 Snipe-it 2024-08-03 5.4 Medium
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
CVE-2022-1445 1 Snipeitapp 1 Snipe-it 2024-08-03 5.4 Medium
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
CVE-2022-1155 1 Snipeitapp 1 Snipe-it 2024-08-02 7.4 High
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
CVE-2022-0622 1 Snipeitapp 1 Snipe-it 2024-08-02 5.3 Medium
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0611 1 Snipeitapp 1 Snipe-it 2024-08-02 6.3 Medium
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-0569 1 Snipeitapp 1 Snipe-it 2024-08-02 5.3 Medium
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
CVE-2022-0579 1 Snipeitapp 1 Snipe-it 2024-08-02 6.5 Medium
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
CVE-2022-0178 1 Snipeitapp 1 Snipe-it 2024-08-02 6.3 Medium
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVE-2022-0179 1 Snipeitapp 1 Snipe-it 2024-08-02 5.4 Medium
snipe-it is vulnerable to Missing Authorization
CVE-2024-5685 1 Snipeitapp 1 Snipe-it 2024-08-01 7.6 High
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.