Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-55515

2 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2026-55515

2 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-35cr-9hqq-p2mg

22 дня назад

Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55515

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.

CVSS3: 5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-55515

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...

CVSS3: 5
0%
Низкий
2 месяца назад
github логотип
GHSA-35cr-9hqq-p2mg

Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint

CVSS3: 5
0%
Низкий
22 дня назад

Уязвимостей на страницу