Impact
Snipe‑IT before version 8.7.0 contains a stored cross‑site scripting flaw in DepartmentPresenter::formattedNameLink(). Department names are output unescaped in a fallback branch for users lacking departments.view permission. Users with departments.edit permission can inject arbitrary JavaScript into a department name. When any department member opens their My Assets page, the malicious script executes in the victim’s browser, potentially stealing session cookies, hijacking the user session, defacing the page, or redirecting to phishing sites. The impact is the compromise of confidentiality and integrity of user data and the ability to perform client‑side attacks against end users.
Affected Systems
The affected product is Snipe‑IT by grokability. All releases before 8.7.0, including version 8.6.3, are vulnerable. The flaw arises in the department handling component and affects all users who can edit a department. If a database contains a crafted department name, any user who views the department’s assets will be exposed.
Risk and Exploitability
The CVSS score of 5.1 marks the vulnerability as moderate, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Exploitation requires the attacker to have permissions to edit a department, which typically implies an admin or privileged account. If the attacker has such access, the flaw can be leveraged against all members of the department when they access their asset lists. Because the impact is client‑side code execution and the attacker does not need to compromise the server, the risk is contained to the affected user base but could be abused for phishing or credential theft. Overall, the urgency of applying a fix is moderate but recommended as soon as possible.
OpenCVE Enrichment