CVE-2024-51094: High severity snipe-it vulnerability
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51094?
CVE-2024-51094 has been classified as a low-severity vulnerability due to its low-privileged attack vector.
How do I fix CVE-2024-51094?
To remediate CVE-2024-51094, upgrade Snipe-IT to the latest version where the vulnerability is patched.
What impact does CVE-2024-51094 have on Snipe-IT users?
CVE-2024-51094 allows a low-privileged attacker to inject malicious code in the profile name, which could be executed upon data export.
Which versions of Snipe-IT are affected by CVE-2024-51094?
CVE-2024-51094 specifically affects Snipe-IT version 7.0.13.
Who is vulnerable to CVE-2024-51094?
Any user of Snipe-IT version 7.0.13 could be vulnerable to CVE-2024-51094 if they export data from the People Management page.