CVE-2021-4018: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published Dec 1, 2021
·Updated
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Snipeitapp Snipe-it<5.3.3
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-4018?
CVE-2021-4018 is a vulnerability in the snipe-it software that allows for Cross-site Scripting (XSS) attacks.
2
What is the severity of CVE-2021-4018?
The severity of CVE-2021-4018 is medium, with a CVSS score of 5.4.
3
How does CVE-2021-4018 affect snipe-it?
CVE-2021-4018 affects snipe-it versions up to (but not including) 5.3.3, allowing for Cross-site Scripting (XSS) attacks.
4
How can I fix CVE-2021-4018?
To fix CVE-2021-4018, update your snipe-it installation to version 5.3.3 or higher.
5
Where can I find more information about CVE-2021-4018?
You can find more information about CVE-2021-4018 at the following references: [GitHub](https://github.com/snipe/snipe-it/commit/ff81e6d5366c2cfb15618793ad919ae4cbb3ac57), [Huntr](https://huntr.dev/bounties/c14395f6-bf0d-4b06-b4d1-b509d8a99b54).