Snipeitapp

Snipe-it

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 08.06.2026 15:41:01
  • Zuletzt bearbeitet 09.06.2026 16:41:26

Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which de...

  • EPSS 0.16%
  • Veröffentlicht 26.05.2026 19:30:48
  • Zuletzt bearbeitet 26.05.2026 20:38:06

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is ...

  • EPSS 0.31%
  • Veröffentlicht 26.05.2026 19:29:31
  • Zuletzt bearbeitet 26.05.2026 20:38:35

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API c...

  • EPSS 0.22%
  • Veröffentlicht 26.05.2026 19:27:16
  • Zuletzt bearbeitet 26.05.2026 20:39:22

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • EPSS 0.48%
  • Veröffentlicht 07.05.2026 00:00:00
  • Zuletzt bearbeitet 12.05.2026 20:29:20

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component

Exploit
  • EPSS 0.31%
  • Veröffentlicht 14.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 15:23:59

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via suppl...

  • EPSS 0.46%
  • Veröffentlicht 06.03.2026 16:16:08
  • Zuletzt bearbeitet 17.04.2026 21:30:32

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted f...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 03.02.2026 16:52:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the acces...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 03.12.2025 18:58:47

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 04.12.2025 18:58:57

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.