CVE-2025-65621: XSS
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.3.4 - Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.3.4 - Operational
After upgrading, review and remove any stored XSS payloads that may have been injected by an authenticated low-privileged user, then validate that the malicious content no longer executes in an administrator's session.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65621?
CVE-2025-65621 has a critical severity level due to the potential for privilege escalation via stored XSS.
How do I fix CVE-2025-65621?
To fix CVE-2025-65621, upgrade Snipe-IT to version 8.3.4 or later.
Who is affected by CVE-2025-65621?
CVE-2025-65621 affects all versions of Snipe-IT prior to 8.3.4.
What type of vulnerability is CVE-2025-65621?
CVE-2025-65621 is a stored cross-site scripting (XSS) vulnerability.
Can a low-privileged user exploit CVE-2025-65621?
Yes, a low-privileged authenticated user can exploit CVE-2025-65621 to inject malicious JavaScript.