Snipeitapp

Snipe-it

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 10.07.2026 19:45:14
  • Zuletzt bearbeitet 14.07.2026 15:17:04

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin ...

  • EPSS 0.19%
  • Veröffentlicht 10.07.2026 19:43:56
  • Zuletzt bearbeitet 14.07.2026 12:14:09

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of imp...

  • EPSS 0.38%
  • Veröffentlicht 10.07.2026 19:42:36
  • Zuletzt bearbeitet 14.07.2026 12:14:48

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing ...

  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 19:41:50
  • Zuletzt bearbeitet 14.07.2026 15:17:04

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirec...

  • EPSS 0.19%
  • Veröffentlicht 10.07.2026 19:40:52
  • Zuletzt bearbeitet 14.07.2026 12:41:29

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unass...

  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 19:40:05
  • Zuletzt bearbeitet 14.07.2026 12:29:03

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.07.2026 19:37:54
  • Zuletzt bearbeitet 14.07.2026 12:18:23

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(),...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 10.07.2026 19:36:45
  • Zuletzt bearbeitet 14.07.2026 11:49:24

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the re...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.07.2026 19:35:05
  • Zuletzt bearbeitet 14.07.2026 12:21:23

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authentica...

  • EPSS 0.17%
  • Veröffentlicht 10.07.2026 18:40:42
  • Zuletzt bearbeitet 13.07.2026 16:16:37

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea...