{"id":"CVE-2024-51093","aliases":["GHSA-hw9x-8m75-4vjq"],"url":"https://o3.security/vulnerability/CVE-2024-51093","summary":"Cross Site Scripting vulnerability in Snipe-IT","details":"Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.","published":"2024-11-12T21:15:14.027Z","modified":"2026-04-10T05:16:01.916625Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://gist.githubusercontent.com/Tommywarren/ca70f1c43f4ec34dc19cd13459535780/raw/d13192ae50bc7c024b922412dfa3f530faa8d5db/CVE-2024-51093"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T05:16:01.916625Z"}}