MEDIUM
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session
Published Dec 1, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.19%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.