Listen to this Post
Snipe-IT is a popular open-source IT asset and license management system. Prior to version 8.6.2, a stored DOM-based Cross-Site Scripting (XSS) vulnerability existed in how the application handled manufacturer and supplier names. The root cause lies in the table component, which derives a `data-selected-count-id` attribute directly from the component’s `$name` value. On manufacturer and supplier detail pages, stored names are passed into this component.
The client-side JavaScript later reads this browser-decoded `data-selected-count-id` attribute. It uses this value as a selector and, critically, concatenates `countId.substring(1)` directly into an HTML string. This unsanitized string is then passed to the jQuery `.after()` function, which inserts it into the Document Object Model (DOM).
An attacker can exploit this by creating a malicious manufacturer or supplier name. For example, a name like `x[foo=”>
DailyCVE Form:
Platform: Snipe-IT
Version: <8.6.2
Vulnerability: Stored DOM XSS
Severity: Medium (CVSS 6.3)
date: 2026-08-19
Prediction: 2026-08-19 (Patched)
What Undercode Say:
Analytics:
To check if your Snipe-IT instance is vulnerable, verify the version.
Check the version of your Snipe-IT instance php artisan snipe-it:version
To identify if a payload has been injected, search the database for the malicious pattern in manufacturer or supplier names.
Search for potential XSS payloads in the database (example using MySQL) mysql -u [bash] -p[bash] [bash] -e "SELECT FROM manufacturers WHERE name LIKE '%<svg%' OR name LIKE '%onload%';" mysql -u [bash] -p[bash] [bash] -e "SELECT FROM suppliers WHERE name LIKE '%<svg%' OR name LIKE '%onload%';"
Exploit: (Educational Purposes!)
An attacker can inject a payload by creating or updating a manufacturer or supplier with a crafted name. The following is a proof-of-concept payload that triggers an alert box.
x[foo="><svg/onload=alert(1)>"]>
When an administrator or any user views the detail page of this manufacturer or supplier, the JavaScript code `alert(1)` will execute in their browser.
Protection:
The primary protection is to update Snipe-IT to version 8.6.2 or later. The fix is included in commit grokability/snipe-it@d12ad3d. If an immediate update is not possible, you can implement a web application firewall (WAF) rule to block requests containing suspicious patterns like <svg, onload=, or similar XSS payloads in manufacturer and supplier name fields.
Impact:
Successful exploitation allows an attacker to execute arbitrary JavaScript code in the context of an authenticated user’s session. This can lead to:
– Data Theft: Stealing session cookies, API keys, or other sensitive information displayed on the page.
– Privilege Escalation: Performing actions on behalf of the victim user, potentially including administrative tasks if the victim is an admin.
– Account Takeover: Hijacking the user’s session.
– Defacement: Altering the content of the page as seen by the victim.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

