CVE-2022-1445: Stored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
Published Apr 24, 2022
·Updated
Stored Cross Site Scripting vulnerability in the checkedoutto parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
Affected Software
1 affected component
Snipeitapp Snipe-it<5.4.3
Remediation
Event History
Apr 24, 2022
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1445.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3'.
3
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a severity value of 5.4.
4
Which software versions are affected by the vulnerability?
The Snipe-IT software versions prior to 5.4.3 are affected by the vulnerability.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by using stored cross-site scripting in the checked_out_to parameter.