CVE-2022-32061: XSS
Published Jul 7, 2022
·Updated
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
Affected Software
1 affected component
Snipeitapp Snipe-it=6.0.2
Event History
Jul 7, 2022
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this arbitrary file upload vulnerability?
The vulnerability ID is CVE-2022-32061.
2
What is the severity level of CVE-2022-32061?
The severity level of CVE-2022-32061 is medium with a severity value of 4.8.
3
How does the arbitrary file upload vulnerability in Snipe-IT v6.0.2 occur?
The arbitrary file upload vulnerability in Snipe-IT v6.0.2 occurs in the Select User function under the People Menu component.
4
What can an attacker do with this arbitrary file upload vulnerability?
An attacker can execute arbitrary code by uploading a crafted file.
5
Is there a fix available for CVE-2022-32061?
Currently, there is no known fix for CVE-2022-32061. It is recommended to update to a secure version of Snipe-IT when available.