Snipeitapp

Snipe-it

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.09.2026 13:32:12
  • Zuletzt bearbeitet 19.09.2026 15:17:07

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 09.09.2026 13:32:11
  • Zuletzt bearbeitet 14.09.2026 20:33:55

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepte...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 09.09.2026 13:32:10
  • Zuletzt bearbeitet 14.09.2026 20:35:02

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed com...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 13:32:09
  • Zuletzt bearbeitet 18.09.2026 18:17:19

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outsid...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 09.09.2026 13:32:09
  • Zuletzt bearbeitet 14.09.2026 20:38:00

Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.09.2026 13:32:08
  • Zuletzt bearbeitet 14.09.2026 20:46:16

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CS...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.09.2026 13:32:07
  • Zuletzt bearbeitet 14.09.2026 20:48:28

Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files o...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.09.2026 13:32:07
  • Zuletzt bearbeitet 14.09.2026 20:47:24

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six ...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 09.09.2026 13:32:06
  • Zuletzt bearbeitet 14.09.2026 20:49:15

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators perf...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.09.2026 13:32:05
  • Zuletzt bearbeitet 18.09.2026 18:17:19

Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a writ...