CVE-2021-3931: Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published Nov 13, 2021
·Updated
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Affected Software
1 affected component
Snipeitapp Snipe-it<=5.3.1
Remediation
Event History
Nov 13, 2021
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-3931.
2
What is the title of this vulnerability?
The title of this vulnerability is 'snipe-it is vulnerable to Cross-Site Request Forgery (CSRF).'
3
What is the severity of CVE-2021-3931?
The severity of CVE-2021-3931 is medium with a CVSS score of 4.3.
4
How does CVE-2021-3931 affect snipe-it?
CVE-2021-3931 affects snipe-it by making it vulnerable to Cross-Site Request Forgery (CSRF) attacks.
5
How can I fix the vulnerability in snipe-it?
To fix the vulnerability in snipe-it, you should update to a version later than 5.3.1.