CVE-2021-4108: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4108?
CVE-2021-4108 is a vulnerability in snipe-it that allows for improper neutralization of input during web page generation, resulting in a cross-site scripting (XSS) attack.
How severe is CVE-2021-4108?
CVE-2021-4108 has a severity level of medium with a CVSS score of 6.1.
Which version of snipe-it is affected by CVE-2021-4108?
snipe-it versions up to and exclusive of 5.3.5 are affected by CVE-2021-4108.
How can I fix CVE-2021-4108?
To fix CVE-2021-4108, it is recommended to upgrade to a version of snipe-it that is higher than 5.3.5.
Where can I find more information about CVE-2021-4108?
You can find more information about CVE-2021-4108 at the following references: [GitHub commit](https://github.com/snipe/snipe-it/commit/9d5d1a9f9aae2c8baee48551185da5de0cdb62c2) and [Huntr.dev bounty](https://huntr.dev/bounties/5069a037-040e-4d77-8526-846e65edfaf4).