CVE-2022-3035: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published Aug 29, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
Affected Software
1 affected component
Snipeitapp Snipe-it<6.0.11
Remediation
Event History
Aug 29, 2022
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3035?
The severity of CVE-2022-3035 is medium with a CVSS score of 4.8.
2
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
3
What software is affected by CVE-2022-3035?
Snipe-IT version prior to v6.0.11 is affected by CVE-2022-3035.
4
How can I fix CVE-2022-3035?
To fix CVE-2022-3035, you should update Snipe-IT to version 6.0.11 or later.
5
Where can I find more information about CVE-2022-3035?
You can find more information about CVE-2022-3035 at the following references: [GitHub Commit](https://github.com/snipe/snipe-it/commit/9cf5f30c77df6ab60baab1c0e6bb0b4e773f0eae), [Huntr](https://huntr.dev/bounties/0bbb1046-ea9e-4cb9-bc91-b294a72d1902).