CVE-2022-1380: Stored Cross Site Scripting vulnerability in Item name parameter in snipe/snipe-it
Published Apr 16, 2022
·Updated
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
Affected Software
1 affected component
Snipeitapp Snipe-it<5.4.3
Remediation
Event History
Apr 16, 2022
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-1380.
2
What is the severity of CVE-2022-1380?
The severity of CVE-2022-1380 is critical.
3
What is the affected software?
The affected software is Snipeitapp Snipe-it up to version 5.4.3.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting malicious scripts into the Item name parameter of GitHub repository snipe/snipe-it.
5
How can I fix CVE-2022-1380?
To fix CVE-2022-1380, update the Snipeitapp Snipe-it software to version 5.4.3 or higher.