Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-55474

3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-55474

3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Act ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c6f4-wj38-m3g3

26 дней назад

Snipe-IT vulnerable to directory traversal in displaySig

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55474

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55474

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Act ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-c6f4-wj38-m3g3

Snipe-IT vulnerable to directory traversal in displaySig

0%
Низкий
26 дней назад

Уязвимостей на страницу