Snipeitapp

Snipe-it

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.29%
  • Veröffentlicht 10.07.2026 18:39:22
  • Zuletzt bearbeitet 14.07.2026 14:16:35

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() ...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 18:36:58
  • Zuletzt bearbeitet 13.07.2026 19:17:13

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return imme...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 18:35:49
  • Zuletzt bearbeitet 13.07.2026 17:17:33

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticate...

  • EPSS 0.18%
  • Veröffentlicht 10.07.2026 18:34:15
  • Zuletzt bearbeitet 10.07.2026 21:16:56

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefin...

  • EPSS 0.3%
  • Veröffentlicht 10.07.2026 18:33:09
  • Zuletzt bearbeitet 13.07.2026 16:16:38

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can ove...

  • EPSS 0.22%
  • Veröffentlicht 10.07.2026 18:31:57
  • Zuletzt bearbeitet 14.07.2026 14:16:35

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-au...

  • EPSS 0.33%
  • Veröffentlicht 10.07.2026 18:29:56
  • Zuletzt bearbeitet 10.07.2026 20:16:47

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse out...

  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 18:26:44
  • Zuletzt bearbeitet 10.07.2026 21:16:55

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company...

  • EPSS 0.23%
  • Veröffentlicht 08.07.2026 21:11:19
  • Zuletzt bearbeitet 10.07.2026 19:46:50

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated l...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 20:32:14
  • Zuletzt bearbeitet 10.07.2026 19:48:18

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minu...