CVE-2025-65621

MEDIUM WAF: High
CVSS 5.4 Published: 2025-12-01
CWE-79 CWE-269

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE
Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
snipeitappsnipe-itup to 8.3.4

References

Back to CVE Database