Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-89155
HistoryNov 16, 2021 - 12:00 a.m.

Snipe-IT Cross-site Request Forgery Vulnerability

2021-11-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

31.0%

Snipe-IT is an open source IT asset/license management system. Snipe-IT is vulnerable to cross-site request forgery, which stems from a lack of csrf checksum for POST requests in the software’s view.blade.php file, and can be exploited by attackers to launch cross-site request forgery attacks.

CPENameOperatorVersion
snipe-it snipe-itle5.3.1

0.001 Low

EPSS

Percentile

31.0%

Related for CNVD-2021-89155