Описание
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
Ссылки
- ExploitMitigationThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:snipeitapp:snipe-it:8.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00311
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-285
Связанные уязвимости
CVSS3: 6.5
debian
4 месяца назад
An improper authorization vulnerability in the /api/v1/users/{id} endp ...
CVSS3: 6.5
github
4 месяца назад
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
EPSS
Процентиль: 24%
0.00311
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-285