Back

MEDIUM

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session

Published Dec 1, 2025

Description

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 1, 2025
Updated Jul 5, 2026
Reserved Nov 18, 2025
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jul 5, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-4G25-WJ72-CHXG