Snipe-IT 是一款 IT 资产/许可证管理系统。在 8.7.0 版本之前,拥有 权限的用户可以将标记语言(markup)存储到 字段中,而 会将该值直接作为未转义的 Bootstrap-table 表头标题。当其他用户打开与该字段集关联的资产列表页面时,存储在 中的标记语言会在页面加载时于该用户的 Snipe-IT 会话中执行。这可能导致同源数据泄露,并允许攻击者以受害者的权限执行经身份验证的操作,包括当超级用户查看受影响的列表时实现权限提升。该问题已在 8.7.0 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | < 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63498 | 8.7 HIGH | Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API |
| CVE-2026-63493 | 8.6 HIGH | Snipe-IT: 2FA bypass via the API token flow |
No comments yet