Snipe-IT Flaw Chained: XSS (CVE-2025-59712) to RCE (CVE-2025-59713) Achieves Full Server Compromise, PoC Released
ID: 0e801420-7876-5bcf-94d0-b7ec692174d3
STIX ID: report--0e801420-7876-5bcf-94d0-b7ec692174d3
Feed Name: securityonline.info
Threat Score
Synacktiv disclosed two critical Snipe-IT vulnerabilities (CVE-2025-59712: stored XSS in the User-Agent field; CVE-2025-59713: unsafe PHP unserialize in ActionlogsTransformer.php) that can be chained by a low-privileged user to obtain remote code execution on the Snipe-IT server; a public proof-of-concept exists and fixes were applied in Snipe-IT v8.1.18.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
