An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| snipe/snipe-it(Packagist) | 0 | N/A | N/A |
CVSS Metrics