PT-2026-78578 · Snipe-It · Snipe-It
CVE-2026-61807
·
Published
2026-08-19
·
Updated
2026-08-25
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.6.2
Description
Stored DOM-based Cross-Site Scripting (XSS) occurs when a manufacturer or supplier name is passed as the table component
$name and becomes data-selected-count-id in the resources/views/partials/bootstrap-table.blade.php file. Client-side code reads the browser-decoded countId, uses it as a selector, and concatenates countId.substring(1) into an HTML string that is passed to the jQuery .after() function. An authenticated user viewing the manufacturer or supplier detail page can trigger the execution of arbitrary JavaScript via a crafted name, potentially exposing session data or performing unauthorized actions.Recommendations
Update to version 8.6.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It