Arbitrary File Upload Vulnerability in Snipe-IT by Snipe-IT
CVE-2022-32061

4.8MEDIUM

Key Information:

Vendor

Snipeitapp

Status
Vendor
CVE Published:
7 July 2022

What is CVE-2022-32061?

An arbitrary file upload vulnerability exists within the Select User function under the People Menu component of Snipe-IT v6.0.2. This flaw allows attackers to upload crafted files, potentially leading to the execution of arbitrary code on the server. By exploiting this vulnerability, attackers can unilaterally execute malicious scripts, compromising the integrity and security of the affected application.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.