
Cloud Vulnerability DB
A community-led vulnerabilities database
Snipe-IT before version 6.0.14 was identified with a Cross-Site Scripting (XSS) vulnerability (CVE-2022-44380) affecting the View Assigned Assets functionality. The vulnerability was discovered by Charalampos Maraziaris and disclosed on December 23, 2022 (Census Labs).
The vulnerability exists in the 'Account' drop-down menu on the top-right of the app's UI, specifically when users select the 'View Assigned Assets' option. The issue stems from improper content rendering in the account/view-assets view (/resources/views/account/view-assets.blade.php) where the title is drawn from the database without proper HTML entity escaping in the Laravel Blade framework, using {!! ... !!} instead of {{ ... }} (Census Labs).
An attacker could inject malicious JavaScript code into the Accessory and Consumable name fields, which would then be executed in a visitor's browser. By targeting a Super User, an authenticated adversary could achieve privilege escalation, granting themselves Super User status (Census Labs).
The stored XSS attack can be performed by an adversary with Accessory.CREATE permissions (to insert an Accessory title in the database) and Accessory.CHECKOUT permissions (to assign this Accessory to any user). Similarly, for Consumables, the attack requires Consumable.CREATE and Consumable.CHECKOUT permissions (Census Labs).
The vulnerability was patched in Snipe-IT version 6.0.14. Organizations are strongly recommended to upgrade to this version or later to address the XSS vulnerability (Census Labs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."