Snipeitapp

Snipe-it

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 09.09.2026 13:32:25
  • Zuletzt bearbeitet 16.09.2026 20:28:24

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from a...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.09.2026 13:32:25
  • Zuletzt bearbeitet 16.09.2026 20:28:31

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or cons...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.09.2026 13:32:24
  • Zuletzt bearbeitet 16.09.2026 20:28:15

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the number of remaining units befor...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 13:32:23
  • Zuletzt bearbeitet 20.09.2026 01:16:31

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning l...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.09.2026 13:32:23
  • Zuletzt bearbeitet 16.09.2026 20:28:04

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign assets, bypass ch...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 09.09.2026 13:32:22
  • Zuletzt bearbeitet 16.09.2026 20:27:08

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its fi...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.09.2026 13:32:21
  • Zuletzt bearbeitet 16.09.2026 20:26:56

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printall...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.09.2026 13:32:21
  • Zuletzt bearbeitet 16.09.2026 20:27:03

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a deactivated ac...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 13:32:20
  • Zuletzt bearbeitet 16.09.2026 20:26:45

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 09.09.2026 13:32:19
  • Zuletzt bearbeitet 20.09.2026 01:16:30

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject f...