{"id":"CVE-2021-3938","aliases":["GHSA-2cqg-q7jm-j35c"],"url":"https://o3.security/vulnerability/CVE-2021-3938","summary":"snipe-it is vulnerable to Cross-site Scripting","details":"snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","published":"2021-11-13T09:15:07.080Z","modified":"2026-08-27T08:40:40.756602Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"5.4.0"}],"fix":{"url":"https://github.com/snipe/snipe-it/commit/9ed1442bd124710f4178992cc4eca5236c7396b9","label":"snipe/snipe-it@9ed1442"},"references":[{"type":"FIX","url":"https://github.com/snipe/snipe-it/commit/9ed1442bd124710f4178992cc4eca5236c7396b9"},{"type":"FIX","url":"https://huntr.dev/bounties/198a0d67-9189-4170-809b-0f8aea43b063"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:40:40.756602Z"}}