Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Snipe-IT: Stored XSS via inline-served attachment
Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content that is later served same-origin and executes JavaScript in a viewer’s browser. This issue is fixed in version 8.6.2.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Grokability Snipe-IT 跨站脚本漏洞
Vulnerability Description
Grokability Snipe-IT是Grokability公司开源的一套开源IT资产/许可证管理系统。 Grokability Snipe-IT 8.6.2之前版本存在跨站脚本漏洞,该漏洞源于UploadFileRequest仅在PHP finfo报告image/svg+xml时清理SVG内容,且UploadedFilesController在没有使用StorageHelper::allowSafeInline()的情况下内联提供附件,可能允许低权限用户上传活跃的XHTML或XML内容,这些内容随后
CVSS Information
N/A
Vulnerability Type
N/A