Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9hg-f94w-656h

Опубликовано: 14 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

EPSS

Процентиль: 24%
0.00311
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

CVSS3: 6.5
debian
4 месяца назад

An improper authorization vulnerability in the /api/v1/users/{id} endp ...

EPSS

Процентиль: 24%
0.00311
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285