Junglewise Threat Intelligence

CVE-2025-65622: Snipe-IT stored XSS in Locations Country field

CVE-2025-65622 · Severity: medium · CVSS 5.4 · Published 2025-12-01

Technologies: Snipe-It, snipe/snipe-it (Packagist). Vendors: Snipeitapp, Packagist.

Executive brief

Snipe-IT, a popular open-source asset management system, is vulnerable to a security flaw where a low-privileged user can inject malicious scripts into the 'Country' field of a location record. When an administrator or another user views this location, the script runs automatically in their browser. This could allow an attacker to perform unauthorized actions, steal session information, or escalate their privileges within the system.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT versions prior to 8.3.4. The root cause is improper neutralization of user-provided input in the 'Country' field within the Locations module. An authenticated attacker with low-level permissions to manage locations can inject a malicious JavaScript payload. This payload is stored in the database and executes in the context of any user (including administrators) who subsequently views or edits that specific location record. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 8.3.4.

Affected products

  • Snipe-IT Snipe-IT < 8.3.4

Timeline

  • 2025-10-17: disclosed: Vulnerability discovered and vendor notified
  • 2025-10-17: patched: Patch released in version 8.3.4
  • 2025-12-01: advisory: NVD publication date

References

Related threats