⤷ Title: Snipe-IT Flaw Chained: XSS (CVE-2025-59712) to RCE (CVE-2025-59713) Achieves Full Server Compromise, PoC Released
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Asset Management #CVE_2025_59713 #Deserialization #php #rce #Snipe_IT #Synacktiv #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Asset Management #CVE_2025_59713 #Deserialization #php #rce #Snipe_IT #Synacktiv #XSS
Daily CyberSecurity
Snipe-IT Flaw Chained: XSS (CVE-2025-59712) to RCE (CVE-2025-59713) Achieves Full Server Compromise, PoC Released
Synacktiv exposed a critical flaw chain in Snipe-IT. A low-privileged user can exploit a Stored XSS (CVE-2025-59712) to hijack admin sessions and trigger RCE (CVE-2025-59713) via unsafe deserialization.