CVE-2023-5452: Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published Oct 6, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<=6.2.1
6.2.2
Snipeitapp Snipe-it<6.2.2
Remediation
Event History
Oct 6, 2023
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-5452?
The severity of CVE-2023-5452 is medium with a severity value of 5.5.
2
How does CVE-2023-5452 affect snipe/snipe-it?
CVE-2023-5452 affects snipe/snipe-it prior to version 6.2.2, allowing for stored cross-site scripting (XSS) attacks.
3
How can I fix CVE-2023-5452 in snipe/snipe-it?
To fix CVE-2023-5452 in snipe/snipe-it, update to version 6.2.2 or later.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-5452?
The Common Weakness Enumeration (CWE) ID for CVE-2023-5452 is CWE-79.
5
Where can I find more information about CVE-2023-5452?
More information about CVE-2023-5452 can be found at the following references: - [GitHub Commit](https://github.com/snipe/snipe-it/commit/eea2eabaeef16fc8f3a1d61b19c06e9fc8ed942a) - [Huntr Bounty](https://huntr.dev/bounties/d6ed5ac1-2ad6-45fd-9492-979820bf60c8) - [NVD CVE](https://nvd.nist.gov/vuln/detail/CVE-2023-5452)