Arbitrary File Upload Vulnerability in Snipe-IT by Snipe-IT
CVE-2022-32061
4.8MEDIUM
What is CVE-2022-32061?
An arbitrary file upload vulnerability exists within the Select User function under the People Menu component of Snipe-IT v6.0.2. This flaw allows attackers to upload crafted files, potentially leading to the execution of arbitrary code on the server. By exploiting this vulnerability, attackers can unilaterally execute malicious scripts, compromising the integrity and security of the affected application.
