Impact
Snipe-IT versions prior to 8.7.0 handle Custom CSS input without properly escaping the greater‑than (>) and double‑quote (") characters, allowing a superuser to inject arbitrary CSS. By embedding @import or url() references and crafting attribute‑selector rules, the attacker can read CSRF tokens stored in the browser context of other superusers and use those tokens to perform authenticated actions as those users, effectively hijacking their accounts.
Affected Systems
The vulnerability affects the Snipe‑IT asset management application supplied by grokability. All releases earlier than 8.7.0 are impacted; no more granular version ranges are specified by the CNA.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical, and the EPSS score is unknown. The flaw was not listed in the CISA KEV catalog. The likely attack vector is the web interface where Custom CSS can be submitted, requiring that the attacker has superuser authentication. Once injected, the attacker obtains an arbitrary other superuser’s CSRF token and can impersonate that account. The exploitation responsibility depends on the attacker’s ability to obtain superuser privileges or compromise an existing superuser account.
OpenCVE Enrichment