CVE-2021-4130: Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published Dec 18, 2021
·Updated
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Affected Software
1 affected component
Snipeitapp Snipe-it<5.3.6
Remediation
Event History
Dec 18, 2021
CVE Published
via MITRE·04:40 AM
Data Sourced
via MITRE·04:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this snipe-it vulnerability?
The vulnerability ID for this snipe-it vulnerability is CVE-2021-4130.
2
What is the severity of CVE-2021-4130?
The severity of CVE-2021-4130 is high with a CVSS score of 8.8.
3
What does the vulnerability CVE-2021-4130 involve?
CVE-2021-4130 is a Cross-Site Request Forgery (CSRF) vulnerability in snipe-it.
4
How does the CVE-2021-4130 vulnerability affect snipe-it?
The CVE-2021-4130 vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks on snipe-it.
5
How can I fix the CVE-2021-4130 vulnerability in snipe-it?
To fix the CVE-2021-4130 vulnerability in snipe-it, update to version 5.3.7 or later.