Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23j2-r96m-7fq9

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

EPSS

Процентиль: 10%
0.00202
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.1
nvd
2 дня назад

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

CVSS3: 7.1
debian
2 дня назад

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ...

EPSS

Процентиль: 10%
0.00202
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862