Описание
Improper Access Control in snipe-it
Users with no system permissions are able to see and create personal access tokens
Пакеты
Наименование
snipe/snipe-it
composer
Затронутые версииВерсия исправления
<= 5.3.7
5.3.8
Связанные уязвимости
CVSS3: 6.3
nvd
около 4 лет назад
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVSS3: 6.3
debian
около 4 лет назад
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue ...