Snipeitapp

Snipe-it

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.09.2026 13:32:18
  • Zuletzt bearbeitet 16.09.2026 20:25:53

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.che...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.09.2026 13:32:18
  • Zuletzt bearbeitet 16.09.2026 20:26:12

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in ...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 09.09.2026 13:32:17
  • Zuletzt bearbeitet 16.09.2026 20:25:23

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 09.09.2026 13:32:16
  • Zuletzt bearbeitet 20.09.2026 01:16:30

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consen...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 09.09.2026 13:32:16
  • Zuletzt bearbeitet 16.09.2026 20:24:41

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe...

  • EPSS 0.22%
  • Veröffentlicht 09.09.2026 13:32:15
  • Zuletzt bearbeitet 14.09.2026 20:20:32

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-request...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 09.09.2026 13:32:14
  • Zuletzt bearbeitet 14.09.2026 20:29:41

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance ...

  • EPSS 0.19%
  • Veröffentlicht 09.09.2026 13:32:14
  • Zuletzt bearbeitet 14.09.2026 20:27:46

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could ...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 09.09.2026 13:32:13
  • Zuletzt bearbeitet 14.09.2026 20:30:57

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 09.09.2026 13:32:12
  • Zuletzt bearbeitet 14.09.2026 20:33:09

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.