Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Ya3Raj

#20588de 56,337
13.7CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2026-89040
8.3
2026-09-09
Git · Snipe-It · CVE-2026-86771
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.
PT-2026-89041
5.4
2026-09-09
Git · Snipe-It · CVE-2026-86772
Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.