Filtered by vendor Snipeitapp Subscriptions
Filtered by product It Open Source Asset Management Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-25264 1 Snipeitapp 1 It Open Source Asset Management 2026-02-04 6.4 Medium
Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.