{"id":26653,"date":"2025-11-18T13:05:00","date_gmt":"2025-11-18T13:05:00","guid":{"rendered":"http:\/\/localhost\/?p=26653"},"modified":"2025-11-18T13:05:00","modified_gmt":"2025-11-18T13:05:00","slug":"snipe-it-834-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=26653","title":{"rendered":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-18T17:15:27&#8243;,&#8221;description&#8221;:&#8221;Snipe-IT&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211726&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-24576&#8243;,&#8221;CVE-2025-64027&#8243;],&#8221;sourceData&#8221;:&#8221;## **Product Info**\\n    \\n    Snipe-IT is a free and open-source IT asset management system (FOSS) built on **Laravel**. It provides hardware asset tracking, software license management, accessories, and consumables inventory features for IT operations teams. It is actively maintained and updated frequently.\\n    \\n    ### **Summary**\\n    \\n    A reflected cross-site scripting (XSS) vulnerability exists in **Snipe-IT v8.3.4 (build 202118)** within the CSV import workflow. When an invalid CSV file is uploaded, the application returns a **progress_message** value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify the **POST `\/livewire\/update`** request and inject arbitrary JavaScript into the **progress_message** parameter.\\n    \\n    Because the server does not sanitize or validate this field before reflecting it back to the client, the injected payload executes in the browser of any authenticated admin viewing the Import page, leading to arbitrary JavaScript execution in a privileged context.\\n    \\n    ## **Affected Product**\\n    \\n    &#8211; **Product:** snipe-it &#8211; v8.3.4\\n    &#8211; **Vendor:** Grokability\\n    &#8211; **Repository:** [https:\/\/github.com\/grokability\/snipe-it](https:\/\/github.com\/grokability\/snipe-it)\\n    \\n    ## **Affected Component**\\n    \\n    &#8211; CSV Import UI (`\/import`)\\n    &#8211; Livewire frontend component\\n    &#8211; POST `\/livewire\/update` request payload\\n    &#8211; `progress_message` variable\\n    \\n    ## **CVSS v3.1 Base Score**\\n    \\n    AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:H\/I:H\/A:L\\n    \\u003cimg width=\\&#8221;966\\&#8221; height=\\&#8221;216\\&#8221; alt=\\&#8221;Pasted image 20251117030626\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/02613a61-8927-48d2-8d69-7b7c6ccd116b\\&#8221; \/\\u003e\\n    \\n    \\n    \\n    \\n    ## **Attack Vector**\\n    \\n    An attacker must cause the admin to upload an invalid CSV file (or simulate the workflow). During the process, the client sends a Livewire update containing the `progress_message` field. By intercepting this request via a proxy (Burp Suite, MitM, etc.), the attacker can modify the request body and inject JavaScript into the `progress_message`.\\n    \\n    The server accepts the modified input **without sanitization** and reflects the tainted value directly back into rendered HTML. When the admin loads or refreshes the import status screen, the injected payload executes.\\n    \\n    \\n    &#8220;`json\\n    \\u003ciframe src=\\\\\\&#8221;javascript:alert(&#8216;XsS By CyberCrew&#8217;)\\\\\\u003e\\n    &#8220;`\\n    ## **Impact**\\n    \\n    * Execution of arbitrary JS with admin privileges\\n    * Installation of malicious browser-based payloads\\n    * Alteration of Snipe-IT assets, users, or settings\\n    \\n    \\n    ## **Steps to Reproduce (PoC)**\\n    \\n    1. Log into Snipe-IT as an admin.\\n    2. Navigate to **Admin \u2192 Import**.\\n    3. Upload an intentionally invalid CSV file.\\n    \\n    \\u003cimg width=\\&#8221;1118\\&#8221; height=\\&#8221;600\\&#8221; alt=\\&#8221;Pasted image 20251117024547\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/2f28af9c-d669-4d77-ab31-ed79b7b39c66\\&#8221; \/\\u003e\\n    \\n    \\n    4. Intercept the **POST** request to:\\n    \\n    &#8220;`bash\\n    \/livewire\/update\\n    &#8220;`\\n    \\n    \\u003cimg width=\\&#8221;1113\\&#8221; height=\\&#8221;607\\&#8221; alt=\\&#8221;Pasted image 20251117024846\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/7aa1a0b0-0e82-4a9f-8e4a-1870ffe46e79\\&#8221; \/\\u003e\\n    \\n    \\n    5. Modify the `progress_message` value:\\n    &#8220;`json \\n    {\\&#8221;progress_message\\&#8221;:\\&#8221;\\u003ciframe src=\\\\\\&#8221;javascript:alert(&#8216;XsS By CyberCrew&#8217;)\\\\\\u003e\\&#8221;}\\n    &#8220;`\\n    \\n    6. Allow the request to proceed.\\n    7. When the admin returns to the import status view, the JavaScript executes.\\n    \\u003cimg width=\\&#8221;1108\\&#8221; height=\\&#8221;496\\&#8221; alt=\\&#8221;Pasted image 20251117025423\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/8e8e26f4-a02a-4618-875a-70bc97f4f085\\&#8221; \/\\u003e\\n    \\u003cimg width=\\&#8221;1116\\&#8221; height=\\&#8221;599\\&#8221; alt=\\&#8221;Pasted image 20251117025459\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/39764fb3-5680-4fcf-b63b-f22fd427ca13\\&#8221; \/\\u003e\\n    \\n    \\n    \\n    \\n    \\n    ## **References**\\n    \\n    [https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-24576](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-24576)\\n    \\n    ## **Discoverer**\\n    \\n    \u682a\u5f0f\u4f1a\u793eCyberCrew \/ \u30b5\u30a4\u30d0\u30fc\u30af\u30eb\\n    \\n    \u2709\ufe0f \u304a\u554f\u3044\u5408\u308f\u305b\u5148\\n    \u3054\u8cea\u554f\u30fb\u3054\u76f8\u8ac7\u306a\u3069\u3054\u3056\u3044\u307e\u3057\u305f\u3089\u3001\u304a\u6c17\u8efd\u306b\u3054\u9023\u7d61\u304f\u3060\u3055\u3044\u3002\\n    \\n    \ud83c\udfe2 \u682a\u5f0f\u4f1a\u793eCyberCrew\\n    G1@4x\\n    \ud83d\udcde Tel\uff1a 03-6853-5823\\n    \ud83d\udce7 Mail\uff1ainfo@cybercrew.co.jp\\n    \\n    \ud83d\udcc4 \u4f1a\u793e\u6982\u8981\\n    \u9805\u76ee\\t\u5185\u5bb9\\n    \u4f1a\u793e\u540d\\t\u682a\u5f0f\u4f1a\u793eCyberCrew\\n    \u6240\u5728\u5730\\t\u6771\u4eac\u90fd\u5343\u4ee3\u7530\u533a\u5916\u795e\u75301-18-13 \u79cb\u8449\u539f\u30c0\u30a4\u30d3\u30eb6\u968e\\n    \ud83d\udd10 \u4e3b\u306a\u30b5\u30fc\u30d3\u30b9\\n    \ud83d\udee1\ufe0f \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a3a\u65ad\u30fb\u30ea\u30b9\u30af\u8a55\u4fa1\\n    \u7d44\u7e54\u306e\u8106\u5f31\u6027\u3092\u591a\u89d2\u7684\u306b\u5206\u6790\u3057\u3001\u6700\u9069\u306a\u6539\u5584\u7b56\u3092\u63d0\u6848\u3057\u307e\u3059\u3002\\n    \\n    \ud83d\udcbb \u30da\u30cd\u30c8\u30ec\u30fc\u30b7\u30e7\u30f3\u30c6\u30b9\u30c8\\n    \u6a19\u7684\u578b\u30fb\u30b7\u30ca\u30ea\u30aa\u578b\u30fbLLM\u30da\u30f3\u30c6\u30b9\u30c8 \u307e\u3067\u5bfe\u5fdc\u3002\\n    \\n    \ud83c\udf12 \u30c0\u30fc\u30af\u30a6\u30a7\u30d6\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0\\n    \u6a5f\u5bc6\u60c5\u5831\u306e\u6d41\u51fa\u3092\u65e9\u671f\u306b\u691c\u77e5\u3057\u3001\u8fc5\u901f\u306b\u5bfe\u5fdc\u3002\\n    \\n    \ud83c\udfaf RED\u30c1\u30fc\u30e0\u6f14\u7fd2\u30fb\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\\n    \u5b9f\u8df5\u7684\u306a\u653b\u6483\u30b7\u30ca\u30ea\u30aa\u306b\u57fa\u3065\u304f\u9632\u5fa1\u529b\u8a55\u4fa1\u3092\u5b9f\u65bd\u3002\\n    \\n    \ud83e\udde0 \u30bb\u30ad\u30e5\u30a2\u30b7\u30b9\u30c6\u30e0\u8a2d\u8a08\u30fb\u30b3\u30f3\u30b5\u30eb\u30c6\u30a3\u30f3\u30b0\\n    \u958b\u767a\u521d\u671f\u6bb5\u968e\u304b\u3089\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u8003\u616e\u3057\u305f\u8a2d\u8a08\u3092\u652f\u63f4\u3057\u307e\u3059\u3002\\n    \\n    \ud83c\udf10 \u516c\u5f0f\u30b5\u30a4\u30c8\uff1ahttps:\/\/www.cybercrew.co.jp\\n    \ud83d\udd52 CyberCrew \u2014 Your Trusted Security Partner.&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/211726&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.1,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/211726\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-18T17:15:27&#8243;,&#8221;description&#8221;:&#8221;Snipe-IT&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211726&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-24576&#8243;,&#8221;CVE-2025-64027&#8243;],&#8221;sourceData&#8221;:&#8221;## **Product Info**\\n \\n Snipe-IT is a free and open-source IT asset management system (FOSS) built on **Laravel**. It provides&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,50,12,15,13,53,7,11,5],"class_list":["post-26653","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-71","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=26653\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-18T17:15:27&#8243;,&#8221;description&#8221;:&#8221;Snipe-IT&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211726&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-24576&#8243;,&#8221;CVE-2025-64027&#8243;],&#8221;sourceData&#8221;:&#8221;## **Product Info**n n Snipe-IT is a free and open-source IT asset management system (FOSS) built on **Laravel**. It provides...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=26653\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-18T13:05:00+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726\",\"datePublished\":\"2025-11-18T13:05:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653\"},\"wordCount\":799,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.1\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26653#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653\",\"name\":\"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-18T13:05:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26653\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26653#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=26653","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-18T17:15:27&#8243;,&#8221;description&#8221;:&#8221;Snipe-IT&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-18T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211726&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-24576&#8243;,&#8221;CVE-2025-64027&#8243;],&#8221;sourceData&#8221;:&#8221;## **Product Info**n n Snipe-IT is a free and open-source IT asset management system (FOSS) built on **Laravel**. It provides...","og_url":"https:\/\/zero.redgem.net\/?p=26653","og_site_name":"zero redgem","article_published_time":"2025-11-18T13:05:00+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=26653#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=26653"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726","datePublished":"2025-11-18T13:05:00+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=26653"},"wordCount":799,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.1","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=26653#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=26653","url":"https:\/\/zero.redgem.net\/?p=26653","name":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-18T13:05:00+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=26653#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=26653"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=26653#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Snipe-IT 8.3.4 Cross Site Scripting_PACKETSTORM:211726"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26653"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26653\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}