Количество 3
Количество 3
CVE-2026-55469
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
CVE-2026-55469
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an ...
GHSA-xr9m-gphc-9p63
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55469 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55469 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an ... | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
GHSA-xr9m-gphc-9p63 Snipe-IT has a path traversal vulnerability via CSV import `image` field | 1% Низкий | 26 дней назад |
Уязвимостей на страницу