Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment
Cyber News related to CVE-2025-15602
CVE-2025-15602 - Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment ...
56 years ago
CVE-2018-15602 - Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter. ...
7 years ago
CVE-2017-15602 - In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size. ...
6 years ago
CVE-2019-15602 - The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves. ...
6 years ago
CVE-2020-15602 - An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer ...
5 years ago
CVE-2021-46158 - A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a stack based buffer overflow vulnerability while parsing NEU files. This could allow an attacker to ...
2 years ago