An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.

Subscriptions

Vendors Products
Snipeitapp Subscribe
Snipe-it Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 19 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-1236
CPEs cpe:2.3:a:snipeitapp:snipe-it:7.0.13:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 22:45:00 +0000

Type Values Removed Values Added
Description An issue in Snipe-IT v.7.0.13 build 15514 allows a remote attacker to escalate privileges via the file /account/profile of the component "Name" field value under "Edit Your Profile". An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.

Tue, 12 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Description An issue in Snipe-IT v.7.0.13 build 15514 allows a remote attacker to escalate privileges via the file /account/profile of the component "Name" field value under "Edit Your Profile".
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-19T16:48:56.392Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-51094

cve-icon Vulnrichment

Updated: 2024-11-19T16:45:54.751Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T21:15:14.113

Modified: 2025-05-22T17:28:00.107

Link: CVE-2024-51094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses