Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
- https://huntr.dev/bounties/f4420149-5236-4051-a458-5d4f1d5b7abd
No PoCs found on GitHub currently.