VDB
Sign up
MEDIUM4.8

GHSA-r42m-953q-6vjx

Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0)

Quick fix

GHSA-r42m-953q-6vjx — snipe/snipe-it: upgrade to the fixed version with the command below.

composer require snipe/snipe-it:^8.4.1

Details

### Impact Users with component view access could be impacted by an unescaped `notes` column.

### Patches This was patched in https://github.com/grokability/snipe-it/commit/28f493d84d057895fbb93b6570e7393a2c2fa438, and is fixed in v8.4.1 or greater.

### Workarounds None.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/snipe/snipe-it
Introduced in: 0Fixed in: 8.4.1
Fixcomposer require snipe/snipe-it:^8.4.1

References