CVE-2022-44380: XSS
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44380?
CVE-2022-44380 is a vulnerability in Snipe-IT before version 6.0.14 that allows for Cross Site Scripting (XSS) attacks when viewing assigned assets.
How severe is CVE-2022-44380?
CVE-2022-44380 has a severity rating of medium, with a CVSS score of 5.4.
How can I fix CVE-2022-44380?
To fix CVE-2022-44380, you should update Snipe-IT to version 6.0.14 or higher.
What is Cross Site Scripting (XSS)?
Cross Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
Where can I find more information about CVE-2022-44380?
You can find more information about CVE-2022-44380 at the following link: [https://census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/](https://census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/)