logo

Snipe-IT Flaw Chained: XSS (CVE-2025-59712) to RCE (CVE-2025-59713) Achieves Full Server Compromise, PoC Released

ID: 0e801420-7876-5bcf-94d0-b7ec692174d3

STIX ID: report--0e801420-7876-5bcf-94d0-b7ec692174d3

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Synacktiv disclosed two critical Snipe-IT vulnerabilities (CVE-2025-59712: stored XSS in the User-Agent field; CVE-2025-59713: unsafe PHP unserialize in ActionlogsTransformer.php) that can be chained by a low-privileged user to obtain remote code execution on the Snipe-IT server; a public proof-of-concept exists and fixes were applied in Snipe-IT v8.1.18.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.