CyberRota Analysis
AI-GeneratedSnipe-IT versions prior to 8.5.0 are vulnerable due to improper handling of the User-Agent header in the Activity Report CSV, allowing low-privileged authenticated users to inject formula-like content. This could lead to arbitrary code execution when the CSV is opened in spreadsheet applications, posing a significant risk to users who access these reports. Organizations using Snipe-IT should prioritize upgrading to version 8.5.0 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)