Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-03T13:57:44Z",
"nvd_published_at": "2025-12-01T22:15:48Z",
"severity": "MODERATE"
}