CVE-2022-32060: XSS
Published Jul 7, 2022
·Updated
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
Affected Software
1 affected component
Snipeitapp Snipe-it=6.0.2
Event History
Jul 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-32060?
CVE-2022-32060 is an arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2.
2
How does CVE-2022-32060 allow attackers to execute arbitrary code?
CVE-2022-32060 allows attackers to execute arbitrary code by uploading a crafted file.
3
What is the severity of CVE-2022-32060?
CVE-2022-32060 has a severity rating of medium (4.8).
4
How can I fix CVE-2022-32060?
To fix CVE-2022-32060, update your Snipe-IT software to version 6.0.3 or later.
5
What is the CWE ID for CVE-2022-32060?
The CWE ID for CVE-2022-32060 is CWE-79.