CVE-2021-393113.11.2021, 09:15snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)CSRFEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST4.3 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N@huntrdevCNA4.3 MEDIUMNETWORKLOWNONECVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 33%VendorProductVersionsnipeitappsnipe-it𝑥≤ 5.3.1𝑥= Vulnerable software versionsKnown Exploits!https://huntr.dev/bounties/03b21d69-3bf5-4b2f-a2cf-872dd677a68fhttps://huntr.dev/bounties/03b21d69-3bf5-4b2f-a2cf-872dd677a68fCommon Weakness EnumerationCWE-352 - Cross-Site Request Forgery (CSRF)The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.Referenceshttps://github.com/snipe/snipe-it/commit/0d811d067c8e064252c0143c39d6cd4c3133679ehttps://huntr.dev/bounties/03b21d69-3bf5-4b2f-a2cf-872dd677a68fhttps://github.com/snipe/snipe-it/commit/0d811d067c8e064252c0143c39d6cd4c3133679ehttps://huntr.dev/bounties/03b21d69-3bf5-4b2f-a2cf-872dd677a68f