CVE-2019-10118: XSS
Published Mar 27, 2019
·Updated
Snipe-IT before 4.6.14 has XSS, as demonstrated by logmeta values and the user's last name in the API.
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<4.6.14
4.6.14
Snipeitapp Snipe-it<4.6.14
Remediation
Patch Available
Event History
Mar 27, 2019
CVE Published
via MITRE·03:54 AM
Data Sourced
via MITRE·03:54 AM
Description
May 14, 2022
Advisory Published
01:14 AM
Frequently Asked Questions
1
What is CVE-2019-10118?
CVE-2019-10118 is a vulnerability in Snipe-IT before version 4.6.14 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2019-10118?
CVE-2019-10118 has a severity rating keyword of 'medium' with a severity value of 6.1 out of 10.
3
What is the affected software version for CVE-2019-10118?
The affected software version for CVE-2019-10118 is Snipe-IT up to version 4.6.14.
4
How can I fix CVE-2019-10118?
To fix CVE-2019-10118, you should update Snipe-IT to version 4.6.14 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2019-10118?
The Common Weakness Enumeration (CWE) for CVE-2019-10118 is CWE-79, which is a weakness related to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').