CVE-2021-3879: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published Oct 19, 2021
·Updated
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Snipeitapp Snipe-it<5.3.0
Remediation
Event History
Oct 19, 2021
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this snipe-it vulnerability?
The vulnerability ID for this snipe-it vulnerability is CVE-2021-3879.
2
What is the severity of CVE-2021-3879?
The severity of CVE-2021-3879 is medium (5.4).
3
What is the affected software for CVE-2021-3879?
The affected software for CVE-2021-3879 is snipe-it version up to exclusive 5.3.0.
4
How can I fix CVE-2021-3879?
To fix CVE-2021-3879, users should update snipe-it to version 5.3.1 or later.
5
What is the CWE ID for CVE-2021-3879?
The CWE ID for CVE-2021-3879 is CWE-79.