CVE-2021-3961: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3961?
CVE-2021-3961 is a vulnerability in snipe-it that allows for unfiltered user input to be displayed on web pages, leading to potential cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-3961?
The severity of CVE-2021-3961 is high, with a severity score of 5.4.
Which versions of snipe-it are affected by CVE-2021-3961?
snipe-it versions up to and excluding 5.3.2 are affected by CVE-2021-3961.
How can I fix CVE-2021-3961?
To fix CVE-2021-3961, update snipe-it to version 5.3.2 or higher.
Where can I find more information about CVE-2021-3961?
You can find more information about CVE-2021-3961 on the snipe-it GitHub commit page (https://github.com/snipe/snipe-it/commit/7ce5993f5ae9d713a0955c2fd8e2dff7a7ce886e) and on the huntr.dev bounty page (https://huntr.dev/bounties/5987aed5-6613-4937-8a3e-d48009b7da10).