CVE-2021-3938: Cross-site Scripting (XSS) - Generic in snipe/snipe-it
Published Nov 13, 2021
·Updated
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<=5.3.1
5.4.0
Snipeitapp Snipe-it<=5.3.1
Remediation
Event History
Nov 13, 2021
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionSeverityWeakness
Nov 15, 2021
Advisory Published
11:19 PM
Frequently Asked Questions
1
What is CVE-2021-3938?
CVE-2021-3938 is a vulnerability in snipe-it that allows for Cross-site Scripting (XSS) attacks.
2
How severe is CVE-2021-3938?
CVE-2021-3938 has a severity rating of medium, with a CVSS score of 5.4.
3
What is the affected software for CVE-2021-3938?
The affected software for CVE-2021-3938 is snipe-it version up to and including 5.3.1.
4
How can I fix the CVE-2021-3938 vulnerability?
To fix the CVE-2021-3938 vulnerability, you should update snipe-it to version 5.4.0 or later.
5
Where can I find more information about CVE-2021-3938?
More information about CVE-2021-3938 can be found on the NVD website and the GitHub commit and Huntr.dev bounty pages.