Snipe-IT 8.7.0 之前的版本在“自定义 CSS”字段中存在 CSS 注入漏洞。这是由于对大于号(>)和双引号(")的 HTML 编码进行了反向处理,导致净化(sanitization)不完整。超级用户可以通过使用 @import 和 url() 引用的恶意 CSS 载荷,利用属性选择器规则从其他超级用户处窃取 CSRF token,从而实现账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.7.0 |
affected |
8.7.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 0 ~ 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86733 | 7.2 HIGH | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore |
| CVE-2026-86734 | 6.5 MEDIUM | Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field |
| CVE-2026-86735 | 5.0 MEDIUM | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass |
| CVE-2026-86736 | 4.3 MEDIUM | snipe-it before 8.7.0 Checkout Request Counter Integrity Failure |
| CVE-2026-86737 | 4.3 MEDIUM | snipe-it before 8.7.0 Missing Authorization via barcode endpoint |
No comments yet