PT-2026-78578 · Snipe-It · Snipe-It

CVE-2026-61807

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.2
Description Stored DOM-based Cross-Site Scripting (XSS) occurs when a manufacturer or supplier name is passed as the table component $name and becomes data-selected-count-id in the resources/views/partials/bootstrap-table.blade.php file. Client-side code reads the browser-decoded countId, uses it as a selector, and concatenates countId.substring(1) into an HTML string that is passed to the jQuery .after() function. An authenticated user viewing the manufacturer or supplier detail page can trigger the execution of arbitrary JavaScript via a crafted name, potentially exposing session data or performing unauthorized actions.
Recommendations Update to version 8.6.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61807
GHSA-C8QC-WF67-342W

Affected Products

Snipe-It