Impact
Snipe‑IT, an IT asset and license management system, contains a stored cross‑site scripting flaw in releases prior to v8.6.2. The CommonMark parser used by the platform escapes raw HTML but does not sanitize "javascript:" URIs that appear in Markdown links. An attacker with assets.edit permission can place a malicious link in a markdown‑textarea custom field. When another authenticated user opens the asset detail page and clicks that link, the browser executes the injected JavaScript, fulfilling the XSS condition described by CWE‑79.
Affected Systems
All installations of Grokability Snipe‑IT running a version earlier than v8.6.2 are affected. The vulnerability applies to the standard distribution of the application; no additional modules or plugins are required beyond the default markdown integration. Users who possess the assets.edit permission can exploit the flaw, meaning that permission is at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of < 1% denotes a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need access to the Snipe‑IT web interface and the ability to edit Markdown fields, but no elevated system privileges are required. Because the attack vector is the web application, exploitation is limited to environments where the application is exposed and the editor permission is granted.
OpenCVE Enrichment